|
|
|
|
|
by Sporktacular
1021 days ago
|
|
Part of systemic improvement to security comes from the market forces that reward producers putting out carefully designed and tested products and punish producers that don't. Your suggestion of requiring prior notice, coordination, approval etc. incentivises them to defer the cost of proper development until there is a crisis, so they can rush out any rubbish product, and force users and researchers to do their security testing for them. Let them fear the unknown, with their necks on the line, and design accordingly. |
|
It does remove any pressure from companies. Their neck is still on the line.
It adds pressure to companies because it creates a paper trail. It enables good faith companies to work with researchers as well. They can even have researchers contact each other if they are both looking into the same thing.
There's a lot of good that can come of it
Companies can already rush out any product they want with no security. Lack of security is still a risk, regardless of how we address researching vulnerabilities