[Economist] 网络安全的神话(三)

    The myth of cyber-security


    Go a bit slower and fix things

    But setting minimum standards still gets you only so far. Users’failure to protect themselves is just one instance of the general problem with computer security—that the incentives to take it seriously are too weak. Often, the harm from hackers is not to the owner of a compromised device. Think of botnets, networks of computers, from desktops to routers to “smart” light bulbs, that are infected with malware and attack other targets.

    但是设立最低标准所能做的也就仅仅是这样了。用户不能保护自己就是计算机安全领域所面临的一个直接问题,用户通常并不会慎重地处理安全问题。通常来自黑客的攻击所带来的破坏并不是作用于那些被攻破的设备。比如说 botnets ,也就是由计算机到路由器以及智能灯泡组成的计算机网络,会被恶意软件感染然后攻击其他目标.

    Most important, the software industry has for decades disclaimed liability for the harm when its products go wrong. Such an approach has its benefits. Silicon Valley’s fruitful “go fast and break things” style of innovation is possible only if firms have relatively free rein to put out new products while they still need perfecting. But this point will soon be moot. As computers spread to products covered by established liability arrangements, such as cars or domestic goods, the industry’s disclaimers will increasingly butt up against existing laws.


    Firms should recognise that, if the courts do not force the liability issue, public opinion will. Many computer-security experts draw comparisons to the American car industry in the 1960s, which had ignored safety for decades. In 1965 Ralph Nader published “Unsafe at Any Speed”, a bestselling book that exposed and excoriated the industry’s lax attitude. The following year the government came down hard with rules on seat belts, headrests and the like. Now imagine the clamour for legislation after the first child fatality involving self-driving cars.

    企业应当意识到,如果法庭没有强制责任的分配,那么公众意见会这么做。许多计算机安全专家引用到 1960 年代已经不顾安全数十载的美国汽车行业作为对比。在 1965 年 Ralph Nader 出版了畅销书“Unsafe at Any Speed”,在书中揭露和批判了汽车行业的懒散态度。次年,政府通过法规强制规定了诸如安全带和头枕之类的要求。现在设想一下如果自动驾驶导致儿童死亡后所带来的立法呼声。



