4 ms·
I think "trust, but verify" (as mentioned in the article) is a much more useful motto than "never trust anyone". The latter isn't an useful attitude, if you to
by kryptiskt 2y ago
I think "trust, but verify" (as mentioned in the article) is a much more useful motto than "never trust anyone". The latter isn't an useful attitude, if you took it seriously you would have carefully check or rewrite everything from the ground up. And then you'd either have to trust the hardware anyway or enlist in a course on VLSI design. "Trust, but verify" is much more practicable, at least if you don't feel the need to verify absolutely everything[0], but is content with doing spot checks of all the features.
So, good article with a misleading title. Don't be paranoid.
[0] I don't consider 100% test coverage as anywhere near close enough for that.
- fatnoah 2y ago> "Trust, but verify" Even though my entire career has been software, I was an Electrical Engineering major, so I have taken VLSI design (and even designed an 8-bit ALU). My first job was writing embedded software, and would frequently "trust, but verify" the hardware through the use of a logic analyzer. When I pulled out printouts from the analyzer to show the hardware team that the hardware had a bug, the surprised and incredulous look on their faces was priceless. The blow was somewhat softened by the fact that I'd also found a software bug. The constant blame shifting between SW and HW teams is one reason I left that job after less than a year.
- Spivak 2y agoThis is why blameless postmortems are such good thing. Going one step further having a culture where finding a bug or defect in your own code/design is rewarded makes it so people aren't afraid but excited to talk about them.
- ImHereToVote 2y ago"Blame is for small children and God"
- fatnoah 2y ago> This is why blameless postmortems are such good thing. 100%. I'm very much a fan of asking _what_ happened and then figuring out how to prevent it from happening ahead. Look back to inform the future, not to find blame. Ultimately, if 1 person can blow things up, it's a bigger issue at play.
- bitwize 2y ago"Trust, but verify" comes from the Soviet Union and is an example of Russian humor. It helps that the Russian words for "trust" and "verify" rhyme. It really means something like "act like you trust the person, but secretly, don't trust them and double check that they've fulfilled their commitments". Putting on a smiling face and acting as if everybody was acting in good faith, while secretly expecting the stab in the back because you would do the same, was key to diplomacy in the USSR, even between departments of the same government.
- lpribis 2y ago"doveryay, no proveryay". It rolls off the tounge so much better in Russian.
- ZoomZoomZoom 2y agoDon't know how you come up with so much specific implicit meaning for the phrase. It simply means you can have high expectations but never a 100% guarantee. It's interesting to note that English wiki has an article about the phrase, but Russian doesn't.
- bigstrat2003 2y agoIf you have to check up on someone to make sure they aren't screwing up (or misleading you), then you don't actually trust them. Thus, "trust but verify" is not trust at all.
- mistermann 2y ago> I think "trust, but verify" (as mentioned in the article) is a much more useful motto than "never trust anyone". The latter isn't an useful attitude, if you took it seriously you would have carefully check or rewrite everything from the ground up. Not actually. You're describing an abstraction: your opinion/perception of what must/can be done. It is possible to be comfortable with uncertainty and the unknown (everyone already is, but only in certain, intuitive (in large part due to cultural conditioning, which comes in a variety of forms) ways), it's mainly just counter-culture and counter-intuitive, thus needs strategies, and practice(!) (plus some non-trivial multi-level, multi-dimensional recursion....this is what us HN folks are good at, and love though, right? Right?[1]). We've all been through the hard work at least once, in a certain (mostly) shared way. There are other ways though. > "Trust, but verify" is much more practical How do you verify your verification in complex scenarios though? I bet I know: trust/contentment (in your verification skills), though this layer typically is not revealed to us, so causes no psychological unrest ("all is well"), because it does not exist. > Don't be paranoid. What do you think your reaction would be if you discovered this is not just wrong, but backwards? [1] Alternatively: maybe we are only good at it, and only love it, sometimes? But then, "we" is a complex and deep set, into which we have little insight, but also plenty of hallucinated "insight".
- danielmarkbruce 2y agoIn some sense you are saying "i can't stand making people uncomfortable so I contort reality". If you have to verify, you don't trust. Google "trust definition". Here is the first result: "firm belief in the reliability, truth, ability, or strength of someone or something". There is no reasonably sized body of code I ever wrote where I'd have a "firm belief" it was error free. There are many situations where we shouldn't believe someone's work is error free. It's fine. Anyone who has ever worked in a field where it can be shown that some work has an error knows how many errors humans make. Anyone who is honest with themselves in the software business knows just how easy it is to make an error. If you need a pithy phrase: "Assume good intent and capability, but verify work".
- getpost 2y ago> Don't be paranoid. How do you mean? I think the article (and my experience) suggests that you do have to be paranoid. [I looked up paranoid, just to be sure I knew the exact definition, and I didn't. It's an "extreme and irrational" fear. Is looking it up parnoid? Hahaha.] Colloquially, paranoia is extreme and not necessarily irrational. Think of Andy Grove, "Only the paranoid survive." Or Kurt Kobain, "Just because you are paranoid, it doesn't mean they're not after you." Anyway, the way I frame the issue of software quality, is to hold the view that there are always errors, and the best you can do to apply extreme vigilance in attempting to ensure errors occur rarely.
- JohnFen 2y agoI think "trust but verify" is logically identical to "don't trust", to be honest. But trust isn't a binary, all-or-nothing sort of thing. There are always degrees. "Trust but verify" makes that explicit.