3 ms·
It's a fallacy to believe that all projects are just sold to the lowest bidder. There are probably a dozen reasons why something like this might have occurred,
by nness 3y ago
It's a fallacy to believe that all projects are just sold to the lowest bidder.
There are probably a dozen reasons why something like this might have occurred, and not giving the vendors a free pass, but assuming that a more expensive vendor would do a better job with security and reviews is just as likely to be a mistaken belief.
If a project is too expensive for a client to do well, they should not be doing that work in the first place.
- boringg 3y agoIts actually probably more of a situation that a client cant discern quality. Its impossible to tell if the most expensive or least expensive if the best option. How does a non technical/semi technical actually grade this stuff appropriately?
- davemp 3y agoThis is a problem traditionally solved by the professional engineering licensing system. Most engineering curriculum in the USA involve an Engineering Ethics course that goes over such issues. We're quite far from implementing such a system for software "engineers".
- comboy 3y agoJust hire pentesters along with the development team. Make sure they are not affiliates. You can put in contract that as long as security issues are present they need to fix them before getting paid, which seems like a reasonable expectation. Even the best make mistakes, so let's at least leave those which are not trivial. We don't trust building ethics, independent inspector comes and checks if everything is as it should be before it can be used by the public.
- otherme123 3y agoThis can't happen more often than not, because the client has no idea what a pentest is. They don't even know what a is XSS means, or even API. These things are negotiated by people that only can see the frontend, and if it looks great, _snappy_, _flashy_, with random animations and following current trends it's OK. The contractors know and can easily detect this, so they focus on frontend and don't waste their time in behind-the-scenes polish. You don't polish the security or find a costly query that could bring the site to their knees, but you add a scroll-spy that brings some images from nowhere.
- comboy 3y agoInvestors have no idea what thickness the wall should be in their building either. Clients not being experts at the job they are getting somebody else to do is not a new pattern. So while some trust is required, it's best if you can get somebody else to verify. I've seen a few smart clients over the years which when faced with some excuses from a software house hired another one to give them opinion about the codebase and capabilities. It seems pretty intuitive. It seems like a money well spent.
- JohnFen 3y ago> Clients not being experts at the job they are getting somebody else to do is not a new pattern In fact, a whole lot of the time, the entire reason someone hires a professional is precisely because they themselves aren't experts.
- robocat 3y ago> solved by the professional engineering licensing system Good narrative: but certification and guilds do not solve the problem.
- davemp 3y agoNo, but actual liability does.
- robocat 3y agoIf that were true, then there would be zero disasters in high liability countries. liability doesn’t prevent disasters from happening. For example: UK Grenfall towers. https://www.bbc.com/news/uk-61724373 https://www.bbc.com/news/uk-61724373 It is a wrong to assume that only engineers can cause deadly mistakes. Also we have penal liabilities that don’t need licensing: The [UK] Health and Safety at Work Act 1974 is designed to stop employers putting the public at risk, not just employees in the workplace. Individuals can be prosecuted and a serious breach could attract a two-year prison sentence. And sometimes some pretty big exceptions: the [UK] government can't be prosecuted for corporate manslaughter Locally to me in Christchurch, New Zealand, there have been no prosecution for the CTV tower collapse: https://www.nzherald.co.nz/nz/fatal-ctv-building-collapse-police-complete-criminal-investigation/ASPACLQEHJD3KCGVA36MHKNHNM/ https://www.nzherald.co.nz/nz/fatal-ctv-building-collapse-po... https://www.nzherald.co.nz/business/govt-considering-introducing-corporate-manslaughter-law-to-enable-ctv-prosecution/JGZXZODGTUGUEMW3YYOVHT4NDY/ https://www.nzherald.co.nz/business/govt-considering-introdu... The second link is interesting because it looks at changing the law to add liability (not engineers licensing changes ) In both cases, there are multiple layers of failure, and many causes could be asssigned. Especially the CTV building with inspections before collapse and warnings from people working there ignored.
- davemp 3y agoIf you're looking for a perfect solution to pretty much any problem involving humans, I have bad news for you.
- nradov 3y agoHire independent consultants with software experience to work on an hourly basis to write portions of the RFP and evaluate the responses. There is a niche industry of experts who help buyers with this stuff. Of course, if the customer is totally ignorant about software then it can be difficult to know which consultants to trust but generally they can ask around industry circles and check references.
- 2rsf 3y agoYou are right of course, I was just theatrically Exaggerating. If we assume there is no corruption involved, then lack of competence from the project management side can fail such a project. For this example it could be failing to mention or think about the extra load on the first hours in the SOA
- dacryn 3y agoIf my company is anything like the others, its very rarely the lowest bidder who wins at all. Usually there is some sort of RFI process, where they ask a few companies 'hey can you build this for us? What are the types of services you would propose'. The list of companies here is already more or less pre-existing partnerships, or ex colleagues or... (it mostly always contains Microsoft, and your boss is ex Accenture, so it involves Accenture, and for good measure to seem like they are open to other options they invite Deloitte and some other players as well, sometimes even IBM has joined the club again) Then they decide who they deem thrustworthy, and you end up with Microsoft and (insert boss previous employer). So not only do you not get the lowest bidder, you can some veeerrryyy generic company that doesn't care and just sends juniors to solve it. This process is called the RFP. And it typically is far from neutral
- sfn42 3y agoSounds spot on to me. Just let a bunch of unsupervised kids loose to screw shit up as much as they like, then after they've done that for a couple years you call them seniors and charge double for their time.
- newsclues 3y agoYeah, there is probably some minority/equity politics that is giving the contracts to totally incompetent people that have the right gender claims or have the right skin colour.
- Twirrim 3y agoThe way that government procurement often works, it isn't the cheap contractors you end up with, either. Not many companies have the resources or willingness to stick through the long time it often takes to go through the bidding process, nor all of the pre-qualification requirements. The whole process is long and drawn out with all sorts of checks and balances built in to it, based on previous learnings from previous contracts that have failed in various ways (particularly if it has embarrassed an elected figure). No doubt on the back of this failure, there will be more conditions added to the bidding process, making it even harder to find a vendor. Usually by the time the entire process is done, there's not many vendors left and in my experience they're usually not the ones you'd actually want to do the work if you had a choice, just often ones that'll at least get you something.
- ExoticPearTree 3y agoAnd sometimes the technology becomes close to not supported and you end up creating a new project with 5 year old technology because of the drawn out bidding process.