Holding developers liable for security flaws

A recent story on ZDNet quotes a security consultant as saying that developers should be held liable for security flaws.

Seems to me that an employer should certainly make developers accountable for the quality of their work. And without the proper oversight, management and practices, poorly organized employers will quickly run out of qualified employees. But it's the entity that is selling the software or service that should be held liable.

In general, this article reminds me of just how haphazard so much software development still is today. I've seen many commercial products that were developed by whatever means seemed to work at the time. It's still the wild west out there.


