Developers 'should be liable' for security holes ~ Idiot
This just got pointed out to me this morning.
I did the poll as well and as of right now 4.7% of the people who voted agree with the author; 51.5% believe it is up to the Vendor. Duh!
Why on earth someone would want to place so much responsibility on a developer is beyond me. Personally I would rather think it is the solution/security architects' role to handle the end to end security of an application, and ultimately the management of that organization. Management has to ensure that their product meets their expectations and needs including details such as these. It is up to them to put the methods and processes in place to ensure that these concerns defined and are met otherwise you will get stupid mistakes like the one mentioned in the article.
Failing to Plan is like Planning to Fail.