8 ms·
Stuff like this is why I believe software engineering ought to start requiring a professional license.
by CCRpoundher 3y ago
Stuff like this is why I believe software engineering ought to start requiring a professional license.
- throw_m239339 3y ago> Stuff like this is why I believe software engineering ought to start requiring a professional license. So the developer goes to jail in case of negligence? Not the executives who actually forced bad decisions? Like in the car industry? No. The people here who are pushing for a license to deploy anything every time there is a hacking scandal somewhere just want to stifle innovation, and eliminate competition and create their own little "developer elite" with themselves as gatekeepers.
- the_only_law 3y agoI just want to know what the certification examination that somehow is going to determine the worthiness of every developer across every domain look like.
- insanitybit 3y agoThat's definitely a very spicy take but I think people need to be more willing to engage with the idea. There is a serious problem where software engineers are building systems that, when built poorly, are causing significant harm. If we don't engage with that problem we're going to get regulated in a way that we may not like. edit: Look at how many comments are just attacking a straw man policy. This is why we're going to end up getting regulated in some dumb way - people can't or won't even imagine a situation better than this one.
- ryandrake 3y agoThis is one of the few opinions which are consistently rejected by the HN peanut gallery, unsurprisingly since most of us are developers. OP is brave to outright say it! Any time you bring up the idea of accountability to “engineers” for defects in their software that cause serious, real life harm, you get a litany of excuses in response, instead of good faith debate. If an engineer signs off on a bridge and it collapses, injuring a dozen people, there will at the very least be questions asked, if not more accountability. But if a software engineer implements a shoddy system that gets hacked and results in this kind of very personal data getting exfiltrated, all you get is 1,000 versions of “it’s not the developers’ fault!” and “they were probably under an impossible deadline!” And “bad manager told them what to implement, they had no choice!” and “the market forces this, careful developers can’t compete!” and so on. Saying there should be licensure with revocation as a consequence in extreme cases? Now that’s crazy-talk here!
- zer8k 3y agoYour opinion is admirable but you're missing something. I, as a software engineer, sign nothing. I do not have a license, I do not have a labor union, and I do not have the "professional stature" to tell my boss to fuck off when he suggests something dangerous. The reason engineering disciplines have such benefits is because after enough cars crumbled and bridges fell the leaders in the industry conceded they needed to listen to professionals. I hear similar bad faith arguments like "you can always quit!" or "your job is to write good code!". I can't always quit because I just got done being jobless for 3 months interviewing. My job was never to write good code. It was to deliver something on budget. If it so happens I get the time to write good, safe, code it was either an accident by management or something I did on my spare time. If you think this is a "bad faith" argument for software engineers being unlicensed you have never worked in the industry outside of high speed military stuff. I have no stake in the code I write because the code I write means nothing. I have no one to defend me and nothing to fall back on that qualifies me as an expert that can tell a VP of engineering to fuck off. Software engineering is an over-educated phrase for the new factory worker. We don't send factory workers to the brig for screwing up a widget. Neither will we send software engineers. If you want to change that it begins at the top. You need a labor union and/or an accreditation board backed by the largest companies guiding the industry. For that, I say, good luck. There's no fundamental physics of software engineering. There's no "basic safety" in software engineering. There are N languages and N+1 ways to blow your own foot off. Standardization would not be well received because the language itself would need to be blessed. This works well for the military who likely still runs a copy of GCC from 1992. It does not work for an industry evolving by the day. What does a PE look like in software engineering? What language? What planning framework? What compiler? This isn't even beginning to talk about contending with the fact a licensing scheme would send every H1B in America home and crush companies like InfoSys overnight. There's a lot of capital in just these two places to fight the licensing battle for several generations. Conflating engineering with software is a hazard. Software "engineers" are just laborers. Very well paid, but fundamentally no different than the guy who built your house. You may be able to argue language designers, software architects, etc would need to be "licensed" but the actual people writing the code are digital welders, house builders, and painters. These people are bonded but not licensed (usually). Companies implicitly bond their software engineers by eating the N million dollar cost of a mistake.
- ronsor 3y agoI mean, the camera in question is from China. China is simply not going to care about any new regulation.
- insanitybit 3y agoChina will care a lot about regulations in the US that prevent them from selling products to us. More so when the myriad US allies enforce similar laws, which the US can very trivially influence them to do. Anyway, my point isn't "we should regulate" or that "regulating will work". My point is that we need to start thinking much more seriously about our responsibilities because, if we don't, the government will do that thinking for us.
- SV_BubbleTime 3y agoImporting products made from IP theft is illegal. How effective has that been? (Before you care to answer that, know that I have a product that has been ripped off in China. My code is put onto cloned devices, and you can buy them on Amazon right now. We’ve gone from reporting, to lawyers, to working with customs police in USA, Canada, China, and Europe. We’ve even had multiple state reps, and two US Senators (for both states we produce in) involved. Nothing is effective and China really really really doesn’t care.) Anyone that says “China will care if we just…” has little idea of this situation in my opinion.
- insanitybit 3y agoI'm not saying that it would be the right way to go. I'm saying that other companies absolutely care about US policy. As for IP, this has increasingly led to tensions between the countries. To say that China doesn't care is silly, China cares and they spend a lot of effort making it viable to continue their practices.
- SV_BubbleTime 3y ago>I'm saying that other companies absolutely care about US policy. Yea? Like Amazon and Walmart? It took a long time to get them to take our counterfeits down, and then only apply that to a vendor, so another pops up instantly. Here I am with first hand knowledge of the situation over years of difficulty and finally defeat, but your opinion is good too.
- kodah 3y agoI'd be supportive of licensing but it needs to go after the right things. Currently the industry is dominated by academics who took their CS & CE degrees and made them barriers to entry for jobs. Real software engineering involves very little DS&A. If we were making people demonstrate competency around OWASP on an infrastructure and dynamic application level I think licensure would go a long way.
- Xeoncross 3y agoIt wouldn't work. A ton of recent attacks and crypto all originated outside the US as well. Plenty of porn, scam calls, and war research on weapons systems. There is no way the entire world would agree/require a shared license for writing software.
- insanitybit 3y agoThe US could easily influence other countries here by enforcing labeling of 'non compliant' devices, tariffs, or flat out banning the sale of those items in the US. Consumers could also look at something that is built in the US and understand that it is built to a different standard. Right now I don't think consumers really have a strong sense of "this is going to have worse security than that".
- Xeoncross 3y ago"uh.. yeah. Sure. All this definitely came from licensed software engineers. We pinky-promise. No unregistered hackers or slave labor." - 3rd world company probably The rest of the world really don't care what the US thinks is important. They will do what is barely needed to do commerce with us (sometimes), but that's it.
- insanitybit 3y ago> The rest of the world really don't care what the US thinks is important. That is just mind numbingly wrong.
- Xeoncross 3y agoRead my comments again, I meant they don't intrinsically care.
- insanitybit 3y agoNo one cares about any law by that logic. We either inherently, 'intrinsically' care about the thing the law defines, ie: we have an ethical framework that aligns with the law, or, we don't care but we acknowledge the cost of not following the law. Either way, the rest of the world by and large cares deeply about the US and its laws.
- dilap 3y agoI don't think requiring a professional license would result in these cameras being secure. The issue isn't individual developers, but market forces not rewarding making the investment to make software secure. I could imagine things like (spitballing) requiring security audits for this kind of software or, say, assessing very large financial penalties in the event of security flaws being found, working -- those would incentivize the company to make a genuine effort to make their software secure.
- CCRpoundher 3y agoWhy wouldn't it be any different than other Engineering disciplines? A professional license comes with ethics. If you release a product that you certified was good to go but later comes out that you effectively skipped corners, you're out a career.
- dilap 3y agoIs it the licensing that results in mostly safe engineering? I don't know, but I'd guess not -- it's probably more about liability. If a bridge or a balcony or a car or whatever fails, the responsible parties can be held legally liable. That's a strong incentive to get it right. If companies were similarly liable for security bugs, we'd see much more of a focus on that. And this is not an easy problem! It's sort of unsolved, in fact; almost all available software is riddled with security flaws. (And constantly being patched, if the company cares.) So getting this right for e.g. an online security camera, would probably necessitate a completely different approach to engineering. There's no way this would happen just by engineers being "diligent" imo w/o the backing of the company itself.
- throw_m239339 3y ago> A professional license comes with ethics. If you release a product that you certified was good to go but later comes out that you effectively skipped corners, you're out a career. And since there is no professional license there is no need for whatever you call "ethics". You want what, a license to fucking deploy a php script on a server? some html file with javascript in it? fuck that shit. Every time there is that sort of scandal in the news you come here pushing for that stupid idea. The "The Shock Doctrine"...
- OO000oo 3y agoIt's a non-starter. Tech companies would never allow anything remotely like that to happen.
- DecayingOrganic 3y agoEven with heavy licensing in the medical field, research cites medical errors like wrong diagnoses and surgical mishaps causing over 250,000 US deaths yearly [0]. Granted, some studies argue over the exact number, but the core truth remains. Licenses don't eliminate human error. [0] https://www.bmj.com/content/353/bmj.i2139 https://www.bmj.com/content/353/bmj.i2139
- guerrilla 3y agoPerfect is the enemy of good. Licensing could make the situation alot better... or worse.
- pipo234 3y agoA license, that can be revoked. Like a doctors license. (Not just some "seal of professionalism" certificate, like, ITIL, PCI, Prince2 or that garbage of course.) Its an interesting proposition. But thinking it through: suppose the issue were that Hikvision weren't licensed and that therefore all those cameras were illegal. But they're still there, filming. And so will future cameras from certified suppliers that simply never get firmware updates, because the user never enabled them. A professional license will probably help. Another approach would be to completely outlaw cameras in certain locations. But the broader problem is that people like cheap cool new stuff and then neglect it.
- lyu07282 3y agoLike have you seen the code academics write? Who is supposed to license developers, bad software is the result of bad management and profit maximization not giving a shit about software quality. It's just in the neoliberal hell world we live in we can only ever blame the workers of course. The managerial class has so much class solidarity, we just down here idiotic peasantbrained as always.
- CCRpoundher 3y agoIt's not blaming workers, it's why isn't this class of career protected like others in it's class (electrical, mechanical, etc.) A professional license benefits the professional as well as the profession itself as a whole.
- darepublic 3y agoSounds awful and dystopian. Just a big layer of ineffective bureaucracy on top of every else.
- CCRpoundher 3y agoOkay. Would you rather drive on a bridge that was just designed by amateurs in their basement or engineers that are licensed and professionally held responsible if it collapses?
- throw_m239339 3y ago> Okay. Would you rather drive on a bridge that was just designed by amateurs in their basement or engineers that are licensed and professionally held responsible if it collapses? Software engineering doesn't need a bunch of gatekeepers telling developers who can deploy code and who cannot or what technology they should be forced to use. Specific projects in specific domain already are already subject to laws and regulations, there is no need for gatekeeping that profession with a license. Every time there is that sort of scandal in the news you come here pushing for that stupid idea. The "The Shock Doctrine "...
- chickenbittle 3y agoI don't know. After reading through this thread there appears to be a lot of 'software engineers' that lack a lot of basic fundament understandings of Engineering as a professional discipline. Maybe more "gatekeeping" is needed.
- throw_m239339 3y ago> I don't know. After reading through this thread there appears to be a lot of 'software engineers' that lack a lot of basic fundament understandings of Engineering as a professional discipline. the plurality of opinions and solutions is what makes the wealth of the software industry, not people who think they are smarter than everybody else because of the tech they use and want to impose that tech on the rest of us. The industry doesn't need a bunch of self-serving people who could decide who should write, deploy, release programs and who shouldn't.
- squarefoot 3y ago> Stuff like this is why I believe software engineering ought to start requiring a professional license. Many murderers had a regular gun permit, and almost all drivers who killed someone in a car accident because of their negligence had a driving license. A professional license for software engineering would not help at all if not accompanied by a thorough psychological evaluation of the person who is being given access to sensitive personal data.
- lo_zamoyski 3y agoDifficult to generalize. There are varieties of programming and software engineering and varieties of safety and rigor needed. Writing software for a janky little web app vs. phone app for note taking vs. firewall software vs. compilers vs. operating systems vs. operational software for automated trains vs. medical device software. It's probably better to regulate the particular domain.