Orcmid's Lair status 
 
privacy 
 
contact 

2005-03-11

Addressing Customer Demands?

ACM News Service: Companies Seek to Hold Software Makers Liable for Flaws.  This blurb summarizes the tension around product liability for software, especially for security vulnerabilities.  The creation of liability principles might be the death-knell for smaller software firms and yet it seems that something must happen.  The Oracle chief security officer warns that government regulation may be the only possibility unless "software makers demonstrate that they are responsibly addressing customer demands for improved security."

The Wall Street Journal's David Bank article is available after registration at ContraCostaTimes.com.  My favorite additional quotation on the lack of accountability of software makers is this:

"We ought to have some way of holding them accountable," says Daniel Wolf, director of information assurance for the National Security Agency, who oversees a system for certifying the security of software for government use. He says Congress would be quick to intervene "if something bad happens and it's because of bad software."
It also seems that there is a great rush to close the kimono to avoid liability, in that full disclosure may invite action.  It would be interesting to know whether that feared-risk is anywhere as dangerous as the liability that occurs when information is willfully withheld.

And mostly I wonder, "why not transparency for its own sake and out of willful determination to serve our customers, the industry, and society?"

 
Comments: Post a Comment
 
Construction Zone (Hard Hat Area) You are navigating Orcmid's Lair.

template created 2002-10-28-07:25 -0800 (pst) by orcmid
$$Author: Orcmid $
$$Date: 06-02-03 22:46 $
$$Revision: 2 $