>why not put the devs and sysadmins in prison if they didn't follow them
So we should start treating them like licensed engineers... Actually I agree with this.
>why not put the devs and sysadmins in prison if they didn't follow them
So we should start treating them like licensed engineers... Actually I agree with this.
This is bit too far to put onus on devs for security and the comparison is more like apples to oranges with other regular licensed engineers. It hard to justify ROI on Security, if anything it makes it harder to roll out features with more traction.
In the absence of any fine, most companies are comfortable with bit of reputation damage.
When the Minneapolis bridge collapsed there were no criminal charges involved. HN has this obsession with "licensed engineers" as if it completely prevents catastrophe and holds people to the highest standards. It's just a dog and pony show.
I mean, 40 years is a bit longer than the garbage we're making lasts.
And software holds people to exactly zero standards and it shows.