Remix.run Logo
bluGill an hour ago

> If we are going to start punishing companies for security negligence, there are WAY worse cases

Perhaps, but you have to start someplace.

I think we do need to punish companies for security negligence. However the details matter (nobody can be perfect: you need to do something reasonable to stop the known attacks, but I have to agree to allow that you can't be perfect and so someone will get compromised). I'm not sure how to get the details right to cover everything without going too far. If we handwave that away though, eventually somebody will need to get punished for something that someone else got away with not long before.