, 2002-07-11
Does the President's Special Advisor on security really understand the issues security professionals are dealing with?
Expand all |
Post comment
|
National Information Security: Is Clarke the Right Man For the Job?
, 2002-07-11 Does the President's Special Advisor on security really understand the issues security professionals are dealing with?
Expand all |
Post comment
|
|
|
Privacy Statement |
Unfortunatly, the insurance companies writing such policies probably aren't in a position to evaluate the security risks specific companies use, at a fine enough level to make a difference. [1].
Yet Clark doesn't understand, or at least acknowlegde, the most powerful incentive: liability. When he was talking at Berkeley (a rather uninteresting talk, BTW), the first question was about software liability, and he ducked the issues completely. In an era where 50% of the flaws are still buffer overflows (and another good 30-40% due to microsoft's "Integrate everything because it helps our monopoly" strategy), liability is one hell of a lever.
[1] The obvious exception would be discounts for services like Counterpane's.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/94/14161#14161