Advertisement
Promo

Security threats Toolkit

Story: Linux guru argues against security liability

  • Previous comment

Posted by: nbhanji (Friday 19 January 2007, 6:02 PM)

  • Reply

developers not liable

"Microsoft's national technology officer, Jerry Fishenden, who spoke at the hearing, said the responsibility for security breaches should rest firmly with those perpetrating the breaches. "We're making software as secure as we possibly can. People don't look at window-lock makers for the responsibility for burglary — the responsibility tends to rest with perpetrators," said Fishenden."

... I am in agreement with the above statements, we as developers do due diligence to ensure that the code and software we produce is secure. However, due to the nature and interaction with different software on the same system that leads to insecure situation we should not be held liable.

As an example -- door maker built a most secure door possible, but the hinges that were used were not the best -- would this mean that door maker is liable when a burglar breaks into the house?

these are the points to look at
1. home owner bought a mediocre hinges -- should he be liable?
2. hinge maker made mediocre product -- should he be liable?
3. since door protects the home, door maker should be liable
4. the perpetrator should be held liable because he/she broke the law, not only invaded someones privacy, but also trespassed on private property and borrowed permanently something(s) that did not belong to them.

as you can see we as developers do our best to make the software secure and our reputation lies in making sure that is the case. We are there to meet consumer's needs by providing software that is valueable to them.

For mistakes in grammar, sentences or spelling -- purposely done to mislead the reader from true crux of the arguement.

nb

Private message disabled

nbhanji

nbhanji
IT Consultant, fl
Member since: January 2007

Site Activity Rating:

1

 


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread


Video icon

Video

Sentry Posts Blog

Security Videos by Industry Leaders

The Academy Pro presents vendor and open source security products in video format. The 500+ free videos cover everything from firewalls, penetration testing, IDS/IPS to NAC and anti-spam.... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters