I am very much advocating for new statutes. That's precisely what my post was doing. Companies should not be allowed to externalize costs of bad security on users.
I disagree with the claim that "only companies like Google will be able to afford to operate in that world." That's not how markets work.
1) The impact would be that frameworks would develop with better security. This would result in a slowdown of software engineering. Perhaps it would start to look like any other engineering discipline, where things are analyzed for safety.
2) Every other industry shows that in situations like this, big players are disadvantaged.
The analysis here is pretty basic:
- If I'm running a small $10M startup making a little iPhone app for some obscure task, the risk of legal liability from this is among the smallest of my risks of going under, so I'm incentivized to ignore it. If I were faced with a $400B liability, I declare bankruptcy, so in effect, that's a $10M liability. The expected cost is 5% times 10M = $500k, so it makes sense to spend up to $500k to mitigate a 5% risk.
- If Google has a team working on that same app, and doesn't manage security properly, the $400B liability stays a $400B liability. There is no ROI analysis where it makes sense to build a little app which has a 5% chance of leaking data. Do it right, or don't do it at all. The expected cost to Google here is 5% times $400B = $20B.
This is why, in virtually every other industry, big players are (1) more trusted (2) more expensive, and phrases like "small, fly-by-night operation" exist (and make business sense to run).