ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Scientists: Fight flaws with laws

Lisa M Bowman CNet

Published: 24 Jan 2002 12:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Software makers should be legally liable for security holes in their products, according to a group of US scientists.

The National Academy of Sciences is recommending that policy-makers create laws that would hold companies accountable for security breaches resulting from vulnerable products.

In a report released last week, titled Cybersecurity Today and Tomorrow: Pay Now or Pay Later, NAS researchers urged lawmakers to take "steps that would increase the exposure of software and system vendors and system operators to liability for system breaches."

The researchers also called for laws that would require software makers to report security problems.

Currently, when a malicious hacker exploits a security flaw in a certain software program, a series of finger-pointing ensues, placing blame on everyone from the cracker to the researcher who discovered the problem. Usually, it's only the hacker who faces court action. The software maker, at worst, typically suffers from bad press.

In addition, companies often deny that their software has been exploited, saying they haven't heard any direct reports of security problems. Some claim a flaw discovered by a researcher is only theoretical and couldn't be duplicated in the real world.

But as security concerns mount in the wake of the 11 September attacks, more companies are evaluating the safety of their products and focusing on trust.

Just last week, Microsoft chairman Bill Gates urged his workers to make security the company's "highest priority." In the past, the company focused on adding new features to its software, sometimes at the expense of security. However, in an email sent to Microsoft employees, Gates said the company should work on making its software "so fundamentally secure that customers never even worry about it."


See the Software News Section for the latest headlines on everything from peer to peer clients to Office software and beyond.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
15 out of 42 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Major Investment Bank seeks Quantitative Researcher

My client, one of the worlds leading Investment Banks, are seeking an exceptional candidate to provide quantitative research for their global ...

C#, C++ RESEARCHER / DEVELOPER SOUTH OXFORD

an outstanding Software Engineer with graduate or postgraduate qualifications, preferably with a Masters and PhD in a computing or numerate ...

Computer Vision PhD Algorithm Researcher - Oxford

Senior Computer Vision Scientist wanted for an advanced imaging company. My client is looking for a 1st class postgraduate with a top academic career ...

Discussions

Moley Moley

welcome to www.007trader.com

Saturday 17 May 2008, 11:37 PM

3 posts
Tallin Tallin

welcome to www.007trader.com

Saturday 17 May 2008, 11:11 PM

3 posts
Moley Moley

Pride

Saturday 17 May 2008, 10:10 PM

6 comments

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling