Live data from Hacker News

Executing Software Engineers for Bugs

blog.setec.io

41–50 of 89 posts

Re: Executing Software Engineers for Bugs

#41

Those of you with a membership in ACM or IEEE, I'm interested in hearing your thoughts on why you do. Those of you who don't, would you consider pledging yourself to a code of ethics if they met your requirements? What would those requirements be?

If it were possible to commit programmers to a code of ethics, it would be possible to do what most professions do an organize to protect the careers and incomes of professionals. On top of the code of ethics would soon be refusing to work on any team with H1-Bs, just as doctors, lawyers, and accountants don't work with any peers who haven't passed the same qualification hurdles as they have. I don't like the idea of…

Economically putting up barriers for the sake of it (aside from valid issues of qualification required for the public good) is bad policy. It's good for the people who can get the qualification, but bad for everyone else. When you average it out, it's worse for society as a whole (this is roughly implied by the Welfare Theorem's of economics).

Your argument that other professions do it is invalid. In fact the government should be more proactive in ensuring that professions only impose valid conditions on employment, and don't add spurious requirements in order to exclude people from the profession, in order to, as you say "protect [their] careers and incomes".

Re: Executing Software Engineers for Bugs

#42
This author's first sentence is: "There is an apocryphal tale I've heard many times about how, in Ancient Rome (or, in some tellings, Greece), the engineers responsible for the construction of an arch were required to stand underneath it as the final wooden supports were taken out."

This story is derived from Law #229 of the Code of Hammurabi (of Babylon). Babylon was not part of Greece, but it was very briefly part of the Roman empire.

" 229 If a builder build a house for some one, and does not construct it properly, and the house which he built fall in and kill its owner, then that builder shall be put to death. "

http://avalon.law.yale.edu/ancient/hamframe.asp

Re: Executing Software Engineers for Bugs

#43
I'm not a big fan of professional bodies or mandatory qualifications. I think these tend towards rent seeking, with these bodies existing mainly to justify their own existence. In the case of software engineering, I'm especially concerned about academics with little real world experience using valid security and privacy issues as an excuse to force their own view of how software engineering should be done on everyone else.

That said, my employer has standards for security and privacy that go well beyond industry norms, so if I was working elsewhere maybe I would feel the need for better standards across the industry.

In my experience, software engineers tend to be conscientious. Caring about the big picture is a big part of open source, hacker and nerd culture. But knowledge is hard to come by. I learnt from the experts, but I doubt most engineers would be able to build a simple CRUD app form scratch without major security holes.

It would be nice to see some best practices around security and privacy emerge without forcing everyone to write Ada or Coq or completely change their approach to writing software.

Re: Executing Software Engineers for Bugs

#45
post #28

Earlier quoted context omitted.

You've stated that it's not more expensive. But everyone in the industry knows otherwise. Unless you can produce some evidence to the contrary, I'm going to insist it's you who is incorrect here.

That's a highly simplistic and incorrect viewpoint—and the correctness of a model is not dependent on popular vote. When looking at increasing quality (essentially, scope) in isolation of systems and the environment in which that quality is created, then the only way to increase quality is to increase cost. That much is true, but it's also incomplete. When looking at and eventually optimizing the whole system—from th…

If true, this is truly amazing. So here's a quick test:

1. Write a letter outlining the above to a VC. Explain how this works in somewhat more detail; 10-15 pages should get it across. Sure it's work. But you seem resolved, and the reward is great. If you pull this off, not only are you gonna get a Turing award, they're going to mint a whole new award and name it after you. Anyway, give it a decent treatment and mail it off.

2. Tell us how that went over.

Hundreds of thousands, heck, millions of pretty smart people have been thinking of ways to solve "the software problem" for over 60 years. Many of those people are smarter than I am, and probably smarter than most of the readership on HN. The actual improvements have been incremental.

I'm not saying there hasn't been improvement. For instance, we tend to write more secure systems these days, but security remains really, really hard. Saying "you're doing it all wrong" to the incredibly smart and driven people I know who are experts in security is pretty bold.

So, I urge you to make a proposal and report back.

Re: Executing Software Engineers for Bugs

#46

Earlier quoted context omitted.

If it were possible to commit programmers to a code of ethics, it would be possible to do what most professions do an organize to protect the careers and incomes of professionals. On top of the code of ethics would soon be refusing to work on any team with H1-Bs, just as doctors, lawyers, and accountants don't work with any peers who haven't passed the same qualification hurdles as they have. I don't like the idea of…

Economically putting up barriers for the sake of it (aside from valid issues of qualification required for the public good) is bad policy. It's good for the people who can get the qualification, but bad for everyone else. When you average it out, it's worse for society as a whole (this is roughly implied by the Welfare Theorem's of economics). Your argument that other professions do it is invalid. In fact the governm…

Programmers have to compete with doctors, lawyers, accountants, actuaries, nurses, dentists, schoolteachers, and pharmacists when we buy a house or seek to influence decisions of the companies where we work. We have to compete with them in income, prestige, bargaining power, moral influence, and credibility with financiers. We have to pay the higher wage rates they have achieved when we need their services.

Unilateral disarmament has already led to a situation where 80,000 unregulated immigrants every year are competing with us while those regulated professions see few or none. We're not going to see them de-regulate in any of our lifetimes, because the theorems of economists don't persuade anyone -- except possibly computer programmers and we don't have any power or influence because we're not united to get any. So the best option is obviously to at least organize to get a fair shake. But so far there are few signs of that.

Re: Executing Software Engineers for Bugs

#47
post #5

We can write software like this. The reason why we don't has been explained many times: It's too expensive, by many orders of magnitude.

This is simply false. True systemic quality will lower costs, speed production, and increase value all at once. The reason is that, beyond a certain organizational complexity, we fail at creating the systems necessary to create the positive feedback loops necessary for quality, low cost, and fast execution to flourish naturally. Instead, we live in dysfunctional organizations where the tradeoffs prevail, and we choos…

"True systemic quality will lower costs, speed production, and increase value all at once."

When you say "true systemic quality" are you speaking far beyond the scope of what any one company is responsible for?

Otherwise, I suspect those replying to you are correct - if bug-free software can be written, quicker and cheaper than software that winds up retaining some bugs, based on work well enough known for 20 years, we'd be seeing someone out there winning with it.

Re: Executing Software Engineers for Bugs

#48
> Unlike our brothers and sisters in the other engineering disciplines, though, software engineering does not have the same history of mandatory formal education.

Was there a time when other engineering disciplines were not formally schooled? Did they develop into having formal education or were they born that way? Is computer programming moving in the same direction via organizations like the ACM?

Can we learn from other fields who have in fact experienced similar issues on some level? Do we need to reinvent the wheel of creating an effective culture that rewards all the values humans desire? What are those? Success, ability to express oneself, ... ?

Re: Executing Software Engineers for Bugs

#49

OK, I think we all can agree that programmers almost never begin a project with the intention of causing harm. All the examples cited involved situations where immense pressure applied by higher-up impel a programmer to knuckle-under and agree to such approaches. The solution that is offered seems very specific to now - we take the fall guy who caved in to one sort of incentive and we put an opposite incentive on him…

The problem becomes... what if the CEO is unaware of it? Volkswagen, for example. It is highly unlikely in my mind that some engineer somewhere in the trenches decided, in desperation, to add in a few lines of code to make sure the engine passed emissions tests. But, do I think the CEO of Volkswagen signed off on adding the code? No. There's a diffusion of responsibility that makes it hard to point to any given perso…

I think that shows the limits of the punishment after the fact approach. The point is to demand that companies create an atmosphere where professionals have some autonomy to make decisions based on their expertise rather than the good of the company. Unfortunately, the trend is things going the other way for virtually all professionals, not simply almost-professionals like programmers.
Post reply on HN