<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1076912843267184&amp;ev=PageView&amp;noscript=1">

RL Blog

|

Lemons and liability: How security warranties could tame the software market

In this ConversingLabs, Daniel Woods shares insights from his research on software warranties and discusses how shifting liability to producers could define the market.

Carolynn van Arsdale
Blog Author

Carolynn van Arsdale, Writer, ReversingLabs. Read More...

ConversingLabs-Season-5-episode-1-Black-Hat-Caffe-cover

Back in 1970, American economist and future Nobel Prize winner George Akerlof published an article in The Quarterly Journal of Economics titled “The Market for ‘Lemons’: Quality Uncertainty and the Market Mechanism.” In it, Akerlof explained the policy changes that occur in response to a lemons market, in which the producer of a good holds greater knowledge about the product they are selling than the buyer. 

One result of this concept of “lemons markets” is warranties, which formalize expectations about the performance of a product and extend the producer’s responsibility for it beyond the point of sale. Daniel Woods, a lecturer in cybersecurity at the University of Edinburgh, noticed this could be applied to the modern-day software development industry.

Woods, who is also a researcher for Coalition, a cyber-insurance and security service provider, believes that the market for software applications is looking a lot like a lemons market, with software buyers struggling to differentiate between secure and insecure software. It’s no surprise, then, that warranties are increasingly common in the software industry, including in the marketplace for cybersecurity tools, where as much as a quarter of endpoint protection products now come with warranties. 

But the mere existence of software warranties doesn’t necessarily change the reality for software buyers. In his talk at this year’s Black Hat USA conference, titled “Lemons and Liability: Cyber Warranties as an Experiment in Software Regulation,” Woods presented the findings of his research that showed that while software warranties may signal higher quality to buyers — which translates into higher customer satisfaction — it's not clear that they succeed in shifting liability for weak security from buyers to producers. 

Woods told host Paul Roberts at Black Hat USA:

“In terms of the question of ‘Do [warranties] transfer risk from the client?’ I don't think it's the case.”  

[ See ConversingLabs: Lemons & Liability: What it Means for Software Applications ]

Who's liable for software security?

Woods' research comes at an interesting time, with policymakers within the United States beginning to shift their attitude on who should bear the responsibility for software insecurity. The White House released the National Cybersecurity Strategy in March 2023, which calls for shifting liability for the security of software products from the end user to the producer.

Commenting on the strategy at Black Hat, Acting National Cyber Director Kemba Walden made the administration's position clear:

“We’ve allowed cybersecurity to devolve to those that are the least capable. Those of us that are more capable should be responsible for cybersecurity risk.” 

Would you like a warranty with your software?

In this ConversingLabs episode, Woods talks about his research on software warranties and discusses how software producers and sellers must be held liable for the security of their products. He also touches on his role at Coalition and the growing role of cyber-insurance in tackling and aiding this challenge. 

Their full conversation is now available to watch — or to listen to wherever you get your podcasts.

Keep learning

Get up to speed with our special report: CSF 2.0 and C-SCRM for Software Risk Management. Plus: See the related expert panel discussion.

Understand key trends and get expert insights with our special report package: The State of Supply Chain Security (SSCS) 2024. Plus: Download the full State of SSCS report.

Learn key factors and best practices for managing software supply chain risk with Gartner's guidance. Plus: Watch the related Webinar and get the Gartner Report courtesy of RL.

Read about why you need to upgrade your AppSec tools for the SSCS era. Plus: Download and share RL's Buyer's Guide for SSCS.


Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for advanced file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

More Blog Posts

Introducing the Unified RL Spectra Suite

Introducing the Unified RL Spectra Suite

RL announced the Spectra Advanced File Analysis and Malware Detection suite, a strategic update of our malware analysis and threat hunting solutions for advanced file analysis and threat detection. Here’s what you need to know.
Read More

    Special Reports

    Latest Blog Posts

    Chinese APT Group Exploits SOHO Routers Chinese APT Group Exploits SOHO Routers

    Conversations About Threat Hunting and Software Supply Chain Security

    Reproducible Builds: Graduate Your Software Supply Chain Security Reproducible Builds: Graduate Your Software Supply Chain Security

    Glassboard conversations with ReversingLabs Field CISO Matt Rose

    Software Package Deconstruction: Video Conferencing Software Software Package Deconstruction: Video Conferencing Software

    Analyzing Risks To Your Software Supply Chain