Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
'Responsible Disclosure' Draft Could Have Legal Muscle
Mark Rasch, 2002-03-11

A proposed Internet standard would dictate how researchers report and vendors close security vulnerabilities. Ignoring it could be risky for either side.

Comments Mode:
Grace Hopper and Liability 2002-03-22
J.R.
Back in the early 80's I had the privledge of listening to a presentation by Grace Hopper. Besides the normal modules of her presention regarding need for growth and where she saw the DP world heading, she addressed the issue of the potential damage of bad code or poorly Q.C.'ed code. Her observation was that she could forsee the day when programers and system designers would be required to have "malpractice insurance" to protect them from lawsuits from users at various levels who become negatively ecconomically impacted by poor system design or bad code (... at the time she didn't even touch on the concept of semi-malicious code intentionally put into systems).

Reading the above article brought all of this back... let's hope that, by whatever means, some form of predictable accountability can be devised before the insurance companys and lawyers begin to realize the ecconomic goldmine of "hi-tech" needs to be mined...

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/66/11344#11344







 

Privacy Statement
Copyright 2009, SecurityFocus