Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In my view, this is the naive outsider perspective.

Security vulnerabilities are everywhere. The old adage 'seek and ye shall find' is king and it doesn't take particular expertise or resources to enter this arena. Moreover, you have hidden cascade/network effects that are growing stronger every day.

With that in mind, one needs to think longer and harder in order to begin to realize what a Good Thing would even be.

When you open the gates of Hell, you have no control over what comes out of it. I'm fully in favor of holding corporations liable when it comes to security vulnerabilities, but making deals with the devil is certainly not the best way of doing that. If this case sets a strong precedent you can expect to see similar speculatory attacks in widely disparate domains, not just medical. I do not share Thomas Ptacek's pessimism re: limited domain applicability of such attacks.

In order to at a minimum avoid chilling effects, you need clear evaluation protocols.

We do not have that in this case, it seems rather that the downside for MW is minimal (and also heavily hedged against).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: