Earlier quoted context omitted.
> When are we going to see legislation enacted to take these people to task? And how would you enforce this ? mandated paid audits provided by companies that have lobbyists and friends in Washington ? Enough with the laws, laws are not an answer to every problems. If there is harm , let the users sue, but stop with your laws...
> And how would you enforce this ? ... mandated paid audits No, that would be quite silly and wouldn't work. It could simply be reactive rather than proactive. When an incident occurs where sensitive user data is exposed, simply launch an investigation into whether there were "adequate" protections in place. If it is found that sensitive data was stored unencrypted, for example, put the directors of the company behin…
If "adequate" protections are missing: Pay every breached user $10.
That way such a breach gets a hefty price-tag and devs/PMs could argue with management, that it is economically feasible to implement these measures.
I know of a PM, that tells devs, that report security-problems inside his product, that they should not care, but instead finish "that news shiny little thing" and that that is their job in his opinion, not detect some strange security-problem.