Live data from Hacker News

Why you've never been in a plane crash

asteriskmag.com

151–160 of 310 posts

Re: Why you've never been in a plane crash

#151
post #127

Earlier quoted context omitted.

There are several ways we could write a list of best practices. But the simplest would be to simply attach a financial cost to leaking any personal data to the open internet. This is essentially how every other industry already works: If my building falls down, the company which made it is financially liable. If I get sick from food poisoning, I can sue the companies responsible for giving me that food. And so on. We…

Software is in a very unique position. It can be attacked all the time with completely impunity. Buildings are completely vulnerable even to simple hammer breaking windows, locks have been basically broken for decades Food processor is easily vulnerable to poisoned potato. Only the software has to take all attacks humans can come up with and withstand it. What other industry has to deal with that? Maybe military, arm…

We don't live in a hard, binary world of extremes. Yes -- buildings and locks are, for the most part, easily compromised. But...

If I make a window of bulletproof glass, it's a lot harder to compromise.

If I surround my building with a wall topped by razor wire, it's a lot harder to compromise. (Unless, of course, I'm making an action film.)

Depending on what or who I'm protecting, I might find these solutions very valuable. Similarly in software, depending on what or who I am protecting, I might be very interested in various security measures.

So far, we've managed to escape an incident where bad actors have compromised systems in a way that's led to severe loss or harm. People are terrible at evaluating risk, so people tend to assume the status quo is okay. It's not, and it's only a matter of time before a bad actor does some real damage. Think 9/11 style, something that causes an immediate reaction and shocks the population. Then, suddenly, our politicians will be all in favor of requiring software developers to be licensed; liability for companies that allow damages; etc.

Re: Why you've never been in a plane crash

#152
post #83
post #24

Earlier quoted context omitted.

Yeah, that's probably why she didn't do it. But if you imagine having to suddenly hire 10,000+ people in conditions which made the previous occupants of those positions so frustrated that they went on strike despite not being allowed to, I guess you can't be too picky with who you hire...

The article makes it pretty clear that Washer was not incompetent at her job, and that the role of the PATCO aftermath hiring spree was not to allow her to get hired when she otherwise couldn't, but to push her to apply when she otherwise might not have for specific personal reasons.

A different, and likely more productive, way of looking at a possible connection between PATCO firings and USAir 1493 is in the form of institutional knowledge lost.

I think a decent argument here is that the mass firing of a large portion of existing ATC personnel damaged the institutional knowledge and rigor of the ATC profession as a whole. What highly technical profession wouldn't be damaged by that? And this damage just increased the risk of serious mishap across the board; it suddenly became much more likely an ATC would make a mistake, and this one is one of those mistakes

Re: Why you've never been in a plane crash

#153

This concept of a blameless culture reminds me of one time when I was talking to a SWE at Facebook around 2010. I don’t know whether the story is actually true or just folklore, but apparently someone brought down the whole site on accident once, and it was pretty obvious who did it. Zuckerberg was in the office and walked up to the guy and said something along the lines of “Just so you are aware, it would probably t…

Look to your left, look to your right, count the heads. Now divide the money that was lost through the number of heads. This is the theoretical ceeling- how much you could make if there were no shareholders and you had your own company - or had a union.

> Now divide the money that was lost through the number of heads. This is the theoretical ceeling

So, if we assume a $10 million loss divided by 100 heads, that means your ceiling is -$100,000 if you were to organize yourself.

Let's see: Six months to build a Facebook clone on an average developer salary plus some other business costs will put you in the red by approximately $100k, and then you'll give up when you realize that the world doesn't need another Facebook clone. So, yeah, a -$100,000 ceiling sounds just about right.

Don't quit your day job – as true as ever.

Re: Why you've never been in a plane crash

#154
post #114
post #33

Earlier quoted context omitted.

TBH having software engineer output in general be liable to some minimum safety, correctness and quality standard would be a god send for the world. But of course the developers will revolt against that.

If you want to call yourself "engineer" then at a minimum all those standards and minimum requirements should apply, no questions asked. I've heard stories of hauling civil engineers out of retirement and in front of a tribunal after some structure that collapsed before it's time, or it was found that the original design was flawed in some way. An engineer "signing off" on something actually means something, with act…

> If you want to call yourself "engineer" then at a minimum all those standards and minimum requirements should apply, no questions asked.

I don’t call myself that so I’m all good. My general vocation is just “technologist”.

Plus: not a protected title in my jurisdiction.

Re: Why you've never been in a plane crash

#155
post #2

...by Kyra Dempsey, a.k.a. Admiral Cloudberg, who has a long series of in-depth airplane crash investigation articles on Medium: https://admiralcloudberg.medium.com/ This is her Medium article on the LAX runway collision: https://admiralcloudberg.medium.com/cleared-to-collide-the-c... - with further details that would probably have distracted from the point she's trying to make in the Asterisk article (e.g. that the…

Thank you for pointing that out! I’m a big fan of Admiral Cloudberg, and was in fact even thinking of her while reading this article, but I did not make the connection. She’s such a fantastic writer.

Does anyone know how she became so good at writing about airline disasters? She doesn’t seem to have any sort of aviation background.

Re: Why you've never been in a plane crash

#156
post #66

This concept of a blameless culture reminds me of one time when I was talking to a SWE at Facebook around 2010. I don’t know whether the story is actually true or just folklore, but apparently someone brought down the whole site on accident once, and it was pretty obvious who did it. Zuckerberg was in the office and walked up to the guy and said something along the lines of “Just so you are aware, it would probably t…

Someone get Zuck an above-average-manager award. But that isn't quite what you want in a blameless culture. The right response looks something like ignoring the engineer, gathering the tech leads and having an extremely detailed walkthrough of exactly what went wrong, how they managed to put an engineer in a position where an expensive outage happened and then they explain why it is never going to happen again. And a…

Instead of a blameless culture, more desirable is a shared responsibility culture.

There are always things the engineer all the way up to the CEO could have done prior and could do after to move the company in a positive direction.

Re: Why you've never been in a plane crash

#157
post #110

Earlier quoted context omitted.

So you propose no idea of "minimal set". If a liability is proposed, it has to be reasonably binary state: compliant/non-compliant. Just like every time, there is no concrete proposal what constitute "minimal set". That's like "make education better", with no concrete plan. We can agree on goal, but on on the method.

There are several ways we could write a list of best practices. But the simplest would be to simply attach a financial cost to leaking any personal data to the open internet. This is essentially how every other industry already works: If my building falls down, the company which made it is financially liable. If I get sick from food poisoning, I can sue the companies responsible for giving me that food. And so on. We…

> If I get sick from food poisoning, I can sue the companies responsible for giving me that food.

Except that is not how food safety is achieved. There are strict rules about how food must be stored, prepared. How the facilities must be cleaned and how the personal must be trained. If these are not met inspectors can and will shut a commercial operation down even if nobody got sick.

And if they follow all best practices they have a good chance of arguing they were not at fault with your illness (besides the point it makes it much less likely to happen in the first place.)

Re: Why you've never been in a plane crash

#158
post #138

Earlier quoted context omitted.

Four million is definitely in the range of an outage at peak, that's not counting reallocated engineering resources to root cause and fix the problem, the opportunity cost of that fix in lost features, extra work by PR, potential contractual obligations for uptime, outage aftershocks, recruiting implications, customer support implications, etc. If you have a once a year outage, how many employee-hours do you think yo…

By that measure a loss of 1 second would be $7k lost revenue. A 100ms outage would be $700. Reality is that revenue wouldn't be lost if you had a 100ms outage, it wouldn't even be noticed.

It doesn't scale linearly.

Re: Why you've never been in a plane crash

#159
post #33
post #28

Earlier quoted context omitted.

With the number of data breaches we see cropping up, I wonder if a similar law could be written to hold companies liable for the safe handling of personal data.

TBH having software engineer output in general be liable to some minimum safety, correctness and quality standard would be a god send for the world. But of course the developers will revolt against that.

I'm am engineer by many definitions, although I don't have or wear a stripey hat, so not the most important definition.

I'm not licensed though and have no signoff rights or responsibilities. If I were to consider signing off on my work or the work of my colleagues after review, the industry would have to be completely different.

I have been in the industry for more than 20 years and I can count the number of times I've had a complete specification for a project I worked on with zero hands. I can't sign off that the work is to spec it the spec is incomplete or nonexistant.

Writing, consuming, and verifying specs costs time and money and adds another layer of people into the process. The cost of failure and the cost to remediate failures discovered after release for most software is too low to justify the cost of rigor.

There's exceptions: software in systems involved with life safety, avionics, and the like obviously have a high cost for failure, and you can't take a crashed plane, turn it off and on and then transport the passengers.

You don't get a civil engineer to sign off on a one-story house in most cases either.

Re: Why you've never been in a plane crash

#160
post #40
post #33

Earlier quoted context omitted.

TBH having software engineer output in general be liable to some minimum safety, correctness and quality standard would be a god send for the world. But of course the developers will revolt against that.

How do you define "minimum safety, correctness and quality standard"?

NCEES which administrates the regulation of Professional Engineers in the US made a Software Engineering Exam which had some standards: https://ncees.org/wp-content/uploads/2016/01/Software-Engine... However so few people took the test they discontinued it. But I at least liked the idea of it.
Post reply on HN