Earlier quoted context omitted.
Do you really think that any legal change would reduce the need for security auditing of apps? I'm afraid that seems awfully unlikely to me. Even if US-based attackers would be deterred, there are plenty of places in the world the Internet reaches but US jurisdiction doesn't.
I think the effort put into securing computers is an inevitable dead-weight loss. Laws against pollution don't make everyone stop polluting; some polluters will just find creative ways to conceal what they're doing. Definitely doesn't mean I think pollution should be legal.
Some problems really are best solved using technical means. If we stop building systems that can be exploited by arbitrary outsiders (yes, this is possible, and probably not that expensive in the long run if we standardize a few good protocols), then we can should be able to reach a point where a certain baseline of security can just be taken for granted.