So is it people's fault or goverments' and in industries'? I see that you are contradicting yourself. If governments industries make more profits then it is in their favour to make systems less secure, so please tell me how this is users' fault?
I never said that anybody intends or makes systems less secure by design. And governments have nothing to do with it. There is no government (not even the batshit stupid EU) that is willing to do anything more than add very modest security patch requirements onto some, not all, software publishers. No government is willing to tank the entire economy with regulations to keep users secure - at least not in the way that you think it should be done.
The reason does not matter. Virtually in all cases, 100% of the responsibility is the user's to secure the system.
No software publisher is going to go beyond a certain point to make their code secure and accommodate whatever system you have concocted. Securing that system is on you - the user. Always has been. Always will be.
You want Microsoft to be held responsible and accountable, then the "Fok Yoo" will come with a huge price tag. Windows will cost $500 or maybe even more for the Home edition. Then Microsoft will charge yearly subscription fees for security patches and hotfixes.
What parts of any of this did you not understand (it applies to all software publishers, not just Microsoft)?:
When you read a Microsoft Service Agreement or Windows EULA (End User License Agreement). You are paying for a product, yet the contract essentially says, "If this breaks your computer or loses your data, it's not our fault."
This "100% responsibility" model isn't just a Microsoft quirk; it is the industry standard for almost all commercial software. There are three primary reasons—legal, economic, and technical—why these agreements are written this way.
1. The "As-Is" Legal Shield
Software is rarely sold as a "guaranteed product" in the same way a toaster is. Instead, it is legally classified as a license to use code. Because code is infinitely complex, Microsoft uses "As-Is" and "Where-Available" clauses to disclaim all warranties.
- Implied Warranties: In standard commerce, there is an "implied warranty of merchantability" (the product must do what it says it does). Microsoft explicitly disclaims this to prevent users from suing if a bug causes a minor inconvenience or a major system crash.
- Limitation of Liability: Most agreements cap Microsoft’s financial responsibility at the amount you actually paid for the software. If Windows crashes and costs a business millions in lost revenue, Microsoft’s legal "shield" ensures they are only liable for the $100–$200 cost of the license.
2. The Problem of "Correlated Risk"
This is the biggest economic reason why software companies can't take 100% responsibility. Unlike a car manufacturer who might have a defect in 5,000 vehicles, a bug in Windows affects 1.4 billion devices simultaneously.
- Systemic Failure: If Microsoft were legally responsible for every data loss or minute of downtime caused by a bug, a single bad update could result in trillions of dollars in claims—literally more money than exists in the company.
- Insurability: No insurance company would ever insure a software developer if they were liable for all "consequential damages" (the indirect losses caused by a software failure).
3. The "Security is a Process" Argument
Microsoft argues that they provide the tools, but you control the environment. They place security responsibility on you because they cannot control:
- Human Error: If you click a phishing link or use "Password123," Microsoft argues they shouldn't be liable for the resulting breach.
- Third-Party Software: Windows runs millions of different apps and drivers. If a 3rd-party printer driver creates a security hole, Microsoft uses their terms to ensure they aren't the ones being sued for the "weakest link" in your specific setup.
Summary of Responsibility
| Feature | Who is responsible? | Why? |
| Code Bugs | User (At your own risk) | Avoids bankrupting the company over one error. |
| System Security | User | Microsoft cannot control your passwords or physical access. |
| Data Backups | User | Storage is local/private; Microsoft has no "custody" of it. |
| Initial Licensing | Microsoft | They must prove they have the right to sell you the code. |