4 ms·
Dead wrong. When lives and money are on the line, there is obligation somewhere along the line back to the source. Maybe it stops elsewhere, maybe it doesn't.
by midas007 12y ago
Dead wrong. When lives and money are on the line, there is obligation somewhere along the line back to the source. Maybe it stops elsewhere, maybe it doesn't. If folks are depending on open source for life-safety or risk the safety of innocent or targeted individuals, there is an obligation at some point to ensure systems are as secure as humanly possible. More importantly, regardless of circumstances, there is a fundamental duty of engineering ethics. [0] They're not just cliche words or some worthless university course, but the implications of how design decisions and construction of something affects the real world. That crappy commit to [project here] might be the difference between someone living and someone dying.
[0] https://en.wikipedia.org/wiki/Engineering_ethics https://en.wikipedia.org/wiki/Engineering_ethics
- ahomescu1 12y agoThe page you linked to starts with: Engineering ethics is the field of applied ethics and system of moral principles that apply to the practice of engineering. The field examines and sets the obligations by engineers to society, to their clients, and to the profession. I read this to only apply to professional engineering, where engineers do work for money or other forms of payment. I don't think freely-given (or almost freely, such as GPL code) hobbyist code should be held to these standards, for one reason: it's being given for free, with no expectations in return. If the developer expects nothing from you in exchange for the code, you shouldn't expect anything more than getting the code as-is.
- vfclists 12y agoI disagree with this. If the hobbyist knows that the code may be used in a critical environment then the hobbyist should withdraw the code or make it very clear its suitability for some task has not been tested. It is rather like asking someone for directions and the person misleads you on the basis that you are not paying him for directions. Ethics always apply whether you are being paid or not.
- ahomescu1 12y ago> If the hobbyist knows that the code may be used in a critical environment then the hobbyist should withdraw the code or make it very clear its suitability for some task has not been tested. It's already made very clear in the license that the code hasn't been tested, and comes with no guarantees. How much clearer than that can it be? Also, you can't really withdraw code from the Internet. Even if you take down the original repository, there may be dozens of forks.
- sitkack 12y agoThat is CYA boilerplate, OpenSSL is most surely designed and implemented for security even if the license says it is for making cupcakes.
- reeses 12y ago"professional engineer" is more than just being paid. It is a regulated term that connotes an ethical code, qualification, and acceptance of responsibility. It can be loosely compared to the bar association in the USA, or many guilds. There are very few "professional software engineers" in the USA. Only a few schools, such as UIUC, have such a program. Software engineer and software architect are meaningless terms. They are self applied yet imply some sort of parity with engineering or architecture. Insert your favorite "if x were built in the same way as software" joke here.
- astrodust 12y agoIf you want "certified software", and this would not be a bad thing for many industries, that's entirely different than open-source software.