, 2001-12-17
Safety standards and civil liability made automobiles safe. It can work for software too.
Expand all |
Post comment
Save the Net, Sue a Software Maker
2001-12-17
Sean, bremerton Wa (4 replies)
Sean, bremerton Wa (4 replies)
Save the Net, Sue a Software Maker
2002-01-12
An old codger that used to be proud of his profession.
An old codger that used to be proud of his profession.
Save the Net, Sue a columnist
2001-12-19
Anonymous (1 replies)
Anonymous (1 replies)
OS and App tools NOT ready for Prime time= lawsuit city!
2001-12-21
we are years away from having tools that coders can use safely (ex: SELinux and CycloneC)! (1 replies)
we are years away from having tools that coders can use safely (ex: SELinux and CycloneC)! (1 replies)

One of the jobs I've done in the recent past is software safety analysis for critical systems, something analogous to UL (Underwriter's Labs). There are several companies in the U.S. and E.U. which do this kind of work; it's time to require major critical software to meet safety and security requirement certification.
Exposure to liability implies that insurance must be available if the industry is to survive; the insurance must be conditional upon successfully passing software safety and security analysis in order for the insurers to limit their risks. The businesses and individual consumers win both ways: they obtain better software, and the right to compensation for damages. They get neither benefit now.
Surely there's room in all those Microsoft billions for a cert of IIS, Exchange, and XP? The cost of certification is clearly a business expense which can be handled as any other business expense. Open source efforts will need an umbrella nonprofit organization to raise money to fund the certifications; but many open source efforts already have such organizations in place. Shareware could even reserve its certified versions for those who actually pay for the software, providing an incentive for users to actually do so, while the not-paid-for-beta version would continue without liability coverage.
The time has come to raise software development into a true engineering discipline. This will never happen until the industry is willing to be responsible for its creations...
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/47/9267#9267