Earlier quoted context omitted.
> How do we decide when it is negligence, and when there was nothing that could be done? This isn't an insoluble issue: courts deal with similar decisions in car crashes, medical malpractice, and many other scenarios. A plaintiff could argue that the respondent should have been aware of certain vulnerabilities because they were widely disseminated, or that certain practices are explicitly warned against in common tra…
Very true, but courts arent known for being up to date with tech.
The privacy wars are about to get a whole lot worse
141–150 of 170 posts
Re: The privacy wars are about to get a whole lot worse
#142Earlier quoted context omitted.
Would a reasonable engineer allow a SQL injection vulnerability to persist in 2016 You are suggesting that a software engineer should be personally liable for the code he writes, just as a civil engineer is liable when he stamps a blueprint. That would be quite a change for our profession.
The reality is that today nobody is responsible for data security. Developers foist the risk onto consumers, who don't have any real choice in the matter, and don't even know what the real risk profile is that they (we) are agreeing to. If you accept that somebody, somewhere needs to be held responsible for data breaches, the most sensible party is us. We have all the domain knowledge and we're the only ones who can…
Doesn't seem to line up very well with "Move fast and break things"
Re: The privacy wars are about to get a whole lot worse
#143Why doesn't Firefox ship with third-party cookies disabled? What would it break that isn't user-hostile? ( edit Chrome, IE, Safari, I understand, but privacy is one of Firefox's main differentiators.)
The Facebook "Like" button for starters.
Is that user-hostile? Is that important?
It's in the eye of the beholder, but if Firefox "doesn't work" for a large tranche of non-technical users, that's a big problem.
It's also not clear how much it would achieve. It's not that difficult to turn a 3rd party cookie into a 1st party one.
Re: The privacy wars are about to get a whole lot worse
#144Earlier quoted context omitted.
> How do we decide when it is negligence, and when there was nothing that could be done? As others have pointed out, that question is one that courts deal with every day in other industries. IANAL but I have some familiarity with the architecture and construction industry, where there are lots of lawsuits around negligence. My understanding is that the question is generally framed as "what would a reasonable professi…
How do architects get away with vague details when lives can be on the line? If they design the building correctly, they should be pushing to make things as explicit as possible so that when contractors make a mistake it is clear where the fault is. It seems unprofessional that they'd be pushing in the other direction.
I don't think many architects would be comfortable taking risks with critical structural details. Also, even if a firm isn't found technically liable for a deadly building failure it can still be very bad for business.
That said I'm sure some architects still put people's lives at risk to avoid liability. I suspect it's similar any other industry where, sometimes, collectively people in a company put the public at risk for the sake of financial gain - pharmaceutical companies, manufacturers, mining companies, etc. No individual feels personally responsible.
Re: The privacy wars are about to get a whole lot worse
#145Earlier quoted context omitted.
> How do we decide when it is negligence, and when there was nothing that could be done? As others have pointed out, that question is one that courts deal with every day in other industries. IANAL but I have some familiarity with the architecture and construction industry, where there are lots of lawsuits around negligence. My understanding is that the question is generally framed as "what would a reasonable professi…
Would a reasonable engineer allow a SQL injection vulnerability to persist in 2016 You are suggesting that a software engineer should be personally liable for the code he writes, just as a civil engineer is liable when he stamps a blueprint. That would be quite a change for our profession.
There are pros and cons to it. It might lead to higher salaries for engineers - liability bringing licensing requirements which could restrict supply.
Re: The privacy wars are about to get a whole lot worse
#146Earlier quoted context omitted.
The reality is that today nobody is responsible for data security. Developers foist the risk onto consumers, who don't have any real choice in the matter, and don't even know what the real risk profile is that they (we) are agreeing to. If you accept that somebody, somewhere needs to be held responsible for data breaches, the most sensible party is us. We have all the domain knowledge and we're the only ones who can…
So -- national building codes for software? Government instpectors who audit code? Building permits required to even write code, or modify existing code? Doesn't seem to line up very well with "Move fast and break things"
When it comes to security around my personal data, I don't want anyone to move fast or break things. Businesses should either not bulk collect identifiable data or treat it with the care and diligence it deserves.
And while we're at it if 20 year old self taught rockstar programmers don't have the skills to do that, maybe they should learn. If you're making web software which stores personal information and you can't name 5 of the OWASP top 10 without looking them up, you're a privacy time bomb. I want my personal data far far away from your product.
When it comes to security, move slowly and fix your shit.
Re: The privacy wars are about to get a whole lot worse
#147Earlier quoted context omitted.
> How do we decide when it is negligence, and when there was nothing that could be done? As others have pointed out, that question is one that courts deal with every day in other industries. IANAL but I have some familiarity with the architecture and construction industry, where there are lots of lawsuits around negligence. My understanding is that the question is generally framed as "what would a reasonable professi…
Would a reasonable engineer allow a SQL injection vulnerability to persist in 2016 You are suggesting that a software engineer should be personally liable for the code he writes, just as a civil engineer is liable when he stamps a blueprint. That would be quite a change for our profession.
Re: The privacy wars are about to get a whole lot worse
#148Earlier quoted context omitted.
In the specific hacks I was thinking of, they didnt hoard and store any info. Equipment was installed that siphoned credit card info from their payment systems. I cant think of a way to run a store without passing credit card info through your payment processing system to the banks.
Agreed, credit cards are a ridiculous necessity. I think in this case the credit card companies should be liable. I am continually amazed by the simple solution bitcoin provides to this problem: instead of me giving you an account number that you (or anyone who gets the number) pull(s) money from, you give me a number that I push money to. It's going to be a long time before that kind of change in our payment systems…
Re: The privacy wars are about to get a whole lot worse
#149Earlier quoted context omitted.
No way. The largest threats to your privacy by several orders of magnitude over the stuff we complain about: - Electric, gas, sewer, water, trash utilities that you basically can't live without. - Thinking of going rustic? Better not own the land in your own name. Most places, parcels are easy to find online. - Property management companies - Sites that facilitate rental applications - Your 100+ year old bank - Credi…
What? Why would Verizon want to connect anything to your mom's car? That's very strange. Could it be that they want to monitor cellphone coverage maybe? Or even monitor their competitors' coverage? It just creeps me the hell out thinking that my telecom would like to connect something to unrelated stuff...
Re: The privacy wars are about to get a whole lot worse
#150Earlier quoted context omitted.
In theory the European Union has a bit better law than the US in this area. I write in theory - because in practice the USA does not need to abide by it - and it is mostly US companies that keep our data. As to the awareness group - I guess this will be controversial - but there are the Pirate Parties with privacy in the core of their ideology. Personally I think that we'll have to give up strict privacy - it is inev…
This is only an inevitability because we do not control our software and hardware. It is entirely possible to replace most of these privacy-destroying technologies and services with privacy-respecting free software solutions. Check out this list of alternatives, for example: https://degooglisons-internet.org/liste?l=en