Somehow I doubt you would apply that argument to designing bridges, or medical practice, or airline piloting, or bus driving, or law, or any of a zillion other professions where credentials are normal and essential to safety and liability. We don't let random schmoes do those other things-- aspiring and starry-eyed or not-- without first proving that they know what they're doing.
We certainly don't wait until the bridge has fallen down or the plane has crashed or the patient has died before we put a burden on the professional to certify their competence.
I don't think it's unreasonable to mandate rigorous certification for life-critical, security-critical, and financial software engineering.
You can write a cookie clicker with a high school degree and put it online if you want. But the moment your cookie clicker takes credit card numbers, you should be legally obligated to know what you are doing or hire someone who does.
One could argue from inspection that, when it comes to security, Equifax's talent is scarcely better than random schmoes, yes.
But it's not just about preventing the hiring of "random schmoes". It's about legally formalizing responsibility and accountability, and the incentive structure that arises from that. As before, this is well-tested in other professions.
Facebook might have made difference decisions if they had special legal obligations regarding "the handling of sensitive personal information." Perhaps their engineers would have thought twice about giving unfettered access to third party APIs if they knew that a breach down the line could ruin their careers.
I would apply the same logic to a lot of professions, actually. If you can do the job, you should be able to. Standards already exist that can be enforced without credentialing. PCI regulates credit card handling, HIPAA regulates health info, etc.
Both PCI and HIPAA have credentialing (and HIPAA has a statutory mandate to require it, though the implementing regulations have not been adopted on the timeline mandated in the statute, and presumably won't be now since the Trump Administration seems to be applying the same neglect and sabotage approach to the required updates to HIPAA standards as to most of the ACA, perhaps because some of the requirements for the former were adopted with the latter or related bills.)
We certainly don't wait until the bridge has fallen down or the plane has crashed or the patient has died before we put a burden on the professional to certify their competence.
I don't think it's unreasonable to mandate rigorous certification for life-critical, security-critical, and financial software engineering.
You can write a cookie clicker with a high school degree and put it online if you want. But the moment your cookie clicker takes credit card numbers, you should be legally obligated to know what you are doing or hire someone who does.