Skip to content

Comment on Should developers be sued for security holes?

Comments

There is a whole lot about a specific deployment that generally isn't known during development (that isn't contracted for the specific task) that is highly relevant to both liability and threats. If I build a tic-tac-toe app, someone uses it to land 747s, and terrorists turn it into a fireball using an obscure timing attack, that's not my fault. Liability should rest with whoever deployed the system, and if they're not comfortable with that they can pay to have the developers or publishers (or insurance companies) adopt more of it. The real problem is that EULAs are impenetrable walls of legalese, half of which is unenforceable in any given jurisdiction, and so go unread, and so there's no pressure on companies to do anything but waive everything they can get away with waiving.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.