6 ms·
If there is one thing that should be crystal clear to everyone its that for some classes of work software should be like real engineering, requiring signoff by
by Devasta 2y ago
If there is one thing that should be crystal clear to everyone its that for some classes of work software should be like real engineering, requiring signoff by the senior engineer with personal liability and fines and jail for negligence.
If the engineers dealing with the Citicorp center had dealt with the problem like software engineers, the fix would have been to update documentation in confluence to not expose the building to high winds and that would have been the end of it.
- jack_riminton 2y agoWhilst I agree in principle, would any Senior Engineer want to work on such a system that had their personal liability attached? I'd want 10's of millions in annual comp just for the risk
- nottorp 2y agoThe real problem is who could afford a system that a competent senior engineer would take personal liability for...
- sfn42 2y agoThe real problem is our entire industry is a giant clusterfuck. Do a 2-week bootcamp, congratulations now you're a software engineer. Every other discipline has education requirements, codified standards for how to do things etc.
- nottorp 2y ago> codified standards for how to do things I don't know you but i bet that if you and me were locked up in a room together for a month we wouldn't be able to 100% agree on "codified standards for how to do things" :) Industry isn't mature enough for that and it's perhaps doubtful that it will ever be. See the halting problem.
- bobnamob 2y agoye gods, can we come up with a "law" to describe appealing to the halting problem? Just because there are unanswered questions that doesn't mean we can't have bare minimum codified standards. Furthermore, standards aren't invalidated just because practitioners disagree with them. Plenty of <insert engineer type>s disagree with the standards body of their respective field, they still follow the standards out of fear of prosecution or simply as a path of least resistance and when those standards are found to be defective, they (generally) evolve.
- nottorp 2y ago> we can't have bare minimum codified standards So, functional, imperative or OOP? :) > Just because there are unanswered questions The halting problem is undecidable. Not undecided. I.e. it has been solved and the answer is "you can't".
- int_19h 2y agoWe don't need to solve the halting problem. We just need to come up with a sensible set of practices that, if followed, make the risks small enough to be considered acceptable. Then we can point at that list and say, "this is what the reasonable expectation of due diligence in software engineering is" - and legally enforce that.
- gorft 2y agoThis is the most pedantic sort of semantic navel-gazing that can only originate in the bowels of an HN thread. Bravissimo, truly.
- nottorp 2y agoYep, now answer me the part about functional, imperative or oop, and come up with a plan to convince everyone.
- ratorx 2y ago> 100% agree I don’t think it’s necessary to agree completely. You could start by codifying a minimal set of things that the majority of people agree on (user data sanitisation, authentication handling etc) and then build on it over time. The standards could also help codify more meta things, like vulnerability policies, reporting and outages. This would be helpful to form a dataset which you can use to properly codify best practices later. The main problem is that this increases the bar for doing software development, but you can get around this by distinguishing serious software industries from others (software revenue over a certain size, industries like fintech, user data handling etc)
- pjmlp 2y agoThankfully not every country out there has such liberties with "enginnering" titles, but yeah that is a problem.
- int_19h 2y agoIt's not the title that's the problem. It's the part where people and go write software that gets deployed at scale in an environment where bugs can cause very real and significant damage (monetary or otherwise).
- pjmlp 2y agoThe title is part of the problem, because it reveals the culture, slapping cool titles without upping oneself to what those titles actually mean. As for the rest, anything that brings computing to level of the rest of other professionals, has my signature. A Software Engineering professor of mine used to say, many applications are akin to buying shoes that randomly explode when tying shoelaces, whereas a minor defect on real shoes gets a full refund.
- nyarlathotep_ 2y ago> The title is part of the problem, because it reveals the culture, slapping cool titles without upping oneself to what those titles actually mean. The irony is there are actual disciplines in software that are worthy of being called "engineering"--how the hell does an engine ECU work with the level of precision that it does? ABS systems? Hell, how about most electronic control systems on an airplane? These are some of the most impressive feats in software development, and I've heard near 0 about any of them. Yet the "industry" is hyper-focused on mashing together "containerized" monstrosities to put strings in databases, or to find a new way to add a chatbot to something that doesn't need it.
- Terr_ 2y agoI'd argue that really says more about capitalism, wealth distribution, and the financialization of everything, as opposed to software stuff per se-- In another area it might be the complete insufficiency of formal botany credentials among Dutch companies growing and trading tulips.
- arethuza 2y agoProfessionally qualified engineers in other fields seem to manage OK?
- nottorp 2y agoThey work with certified components on predictable systems though. You realize that you'd need someone at MS to take liability for Windows before you can sign off anything running on Windows? Or someone at Google if you do a web app that only runs on Chrome, not to mention other browsers.
- Devasta 2y agoWell yeah, but the fact that no one takes responsibility for anything and just smears layers of crap on top of each other is the problem. We have build enormous houses of cards on foundations of quicksand and its causing very real harm, but no one cares because the only thing they'll face consequences for is drops in story points on their sprint or whatever else and nothing for failing to do things that actually matter.
- Symbiote 2y agoSome systems must have these certifications. What OS renders the monitoring screens for air traffic control systems, or railways signalling? Those both have rigorous software engineering behind them — railway signalling is the original of engineered, safety-critical logic systems, starting with mechanical interlocks in 1843. (The signalman physically couldn't move certain levers into bad configurations.)
- lores 2y agoAnd on top of all-certified components, it also requires the chief engineer to have veto power over the system. If business or client asks for features that are potentially insecure (and that's going to be a lot of features), they have to accept being told 'no'. I'm not seeing that happen easily in the software industry.
- oarsinsync 2y ago
- delfinom 2y agoYes? Plenty of non-software engineers do it daily. You start off by having a Professional Liability insurance policy, your company will generally pay for it unless you are a consultant/contractor in which case you bring your own policy. Depending on size of operation, your employer may even indemnify you in the employment contract specifically for even negligence lol. You then do your job correctly. The laws only go after you for liability if you were negligent, i.e. you skipped protocol and policies, you skipped best practices and couldn't justify it, etc. If you weren't negligent and just made an error, great, your insurance covers you. Insurance can also cover negligence too depending on policy, lol https://www.nspe.org/resources/professional-liability/liability-employed-engineers https://www.nspe.org/resources/professional-liability/liabil...
- jack_riminton 2y agoYes and they do non-software engineering Are we going to have international protocols and policies on the best language to use, how to do SQL queries and CSS? no
- gpderetta 2y agoProfessional liability insurance and legal insurance as a minimum.
- teamonkey 2y agoI'm fairly sure Fujitsu do have liability insurance in some form. In a situation like this an insurer is strongly motivated to prove that the company is not at fault, because it doesn't want to pay the bond. The company is also strongly motivated, even though insured, to prove that the company is not at fault, because it doesn't want to have its future insurance rates affected or be sued by the insurer for breaches of terms. Either way, it doesn't help the people affected. Not unless they have personal insurance against workplace computer system errors, in which case their insurance provider is also not motivated to pay out, or to battle a corporation as large as Fujitsu unless there's chance of a class-action suit.
- pjmlp 2y agoYes, that is exactly part of being a Professional Software Engineer entails, and why there are universities assessed by Enginnering Order, and professional exams. Lets stop glueing "engineering" to any job title where someone knows how to write a bunch of code lines.
- arethuza 2y agoThe important bit is that if you screw up badly enough then your professional qualification is removed and you can't do that type of work any more. [NB I am frequently reminded of this point by my wife who is a solicitor].
- pjmlp 2y agoI am aware of that, because I happen to be from a country with an Engineering Order. Another important part is that one might be liable when signing contracts as the responsible Engineer in a project delivery.
- nyarlathotep_ 2y agoDon't understand how this isn't the dominant perspective on this. This title inflation of calling web programmers "engineers" is absurd.
- blackbear_ 2y agoWhy the engineers? Why not putting the liability on the product owner, or the project manager?
- UK-AL 2y agoBecause its a technical guarantee. How is a product manager going to able to personally approve code he can't even read?
- deleted 2y ago[deleted]
- lores 2y agoI'd argue there are vanishingly few engineers who understand all the consequences of even relatively simple code in terms of security and reliability. Every time there is a security breach at a bank or FAANG, some very smart and experienced engineers with the backing of the business didn't understand something. It's downhill from there for most everyone else.
- int_19h 2y agoI'd argue that if there was a demand for software correctness - motivated by, say, legislation applying some baseline standards on such in sensitive applications like money processing - we'd have a lot more smart and experienced engineers focusing on security in particular. The way things are now is because we as an industry have decided that "move fast and break things" is acceptable, and our culture reflects that. So we need to change the culture.
- gorft 2y agoThen maybe those developers shouldn't be employed. Most of us can't do brain surgery, and yet society trundles on without a million people running around poking frontal lobes. "But I really wanna!" has never been a qualification for any job in the history of jobs.
- blackbear_ 2y ago
- verisimi 2y ago> personal liability and fines and jail for negligence Politicians too. And journalists.
- another-dave 2y agoI think there should be definitely higher standards around things in the industry in generally (especially anything that touches health, money etc). But the real culpability here are the upper management who said "we don't believe you" (at the most generous interpretation) when the postmasters said that the system was buggy. > Although many subpostmasters had reported problems with the new software, and Fujitsu was aware that Horizon contained software bugs as early as 1999, the Post Office insisted that Horizon was robust and failed to disclose knowledge of the faults in the system during criminal and civil cases
- bigfatkitten 2y agoSome of the 'engineers' responsible, such as Gareth Jenkins of Fujitsu happily left a paper trail showing their perjury and attempts to pervert the course of justice throughout the legal proceedings. In a just world, he and his co-conspirators would go to jail for what they did, but I don't see it ever happening.
- deleted 2y ago[deleted]
- themk 2y agoAs someone who used to work in electrical engineering but now does software, I almost refuse to use the word engineer for what I now do.
- MrMcCall 2y agoYes, indeed. We are still in the "craft" stage of the process of software development. Engineering is altogether something else than what we're doing. Strangely enough, 30ya, my friend getting his EE Masters was mostly taking programming courses.
- t43562 2y agoI call myself a programmer. It's not engineering or maths or anything else. It's managing complexity and I contend that it's very low cost complexity or we wouldn't be able to afford all the software we use.
- bluecalm 2y agoI don't think it's fair to blame software engineering. Bugs happen, especially where there are no incentives to not have bugs. First of all justice system is to blame. Sentencing someone on assumption that some complicated software worked correctly is criminally stupid and should result on all people involved being barred from the profession. Another thing is that software should be treated as just a tool to help to fulfill legal/accounting requirements. If the software is wrong then the required documents are going to be wrong and that's supposedly auditable. This way there are incentives to produce/finance correct software because what is going to be judge and relied upon is not software itself but what it produces (the documents). Calls to make software engineers responsible will just result in fewer competent people willing to do the work. The justice system is incompetent enough already. Can you imagine lawyers discussing if your off by 1 bug was "criminal negligence" or just a normal mistake that happens? If you going to jail depends on what they decide you will just not take the job and no one sane/competent is going to take it either. The end result is going to be over payed morons writing software and then sometimes going to jail for it - not an improvement over current state of things.
- Devasta 2y agoDoctors, Surgeons, Lawyers are able to manage it fine, software engineering could do it as well. If you could show a constellation of unit and integration tests, well defined schemas and interfaces, for both your code and your dependencies, and a responsible engineering culture then the chances of going to jail are going to be next to nil. People recoil at the idea only because they see that very very little implemented today would be work that anyone would stand by.
- MrMcCall 2y agoWell, the money guys aren't going to let that kind of outlay dip into their country club membership fee allotment, now are they? Your proposal is a brilliant and necessary idea, but we don't run the world, my friend. The people that run it only care about money, and brilliant ideas cost serious money, not to mention committment and patience to follow through. Changing any entrenched status quo is a real slog, for sure. That's why our precious Earth is heating up, daily, to give just one example.