[discuss] Who is responsible for security

>IMHO what is important is that the ISP's sales literature and small
>print should be accurate in describing what they do or don't do in
>terms of end-user security, and in describing what users are left
>to do for themselves.

That would be helpful, but today it's quite clear that they don't. In 
many cases there isn't any sales literature at all, and even the 
simplest technical parameters are unpublished.

If they were, then almost all of our 2 billion users would have no idea 
what it meant.

>Again, there's a car analogy. Car makers are in fact pretty good
>at this now (in countries where I've bought a car) but they
>weren't very good at it fifty years ago.
>When society started to look at it as a consumer protection issue,
>and not as a "Car governance" issue, we got the right answer.

'Consumer protection' generally comes down to resolving financial 
disputes with a supplier.

And the ways that governments make vehicles safer is precisely by 
applying "Car Governance" - a set of complex rules about how the design 
of a car has to meet various criteria.

