I read and understood your original point, and that is what I disagree with. You have made a general point about responsibility, but my point is that if we look at the specifics of this particular issue, one cannot expect software testers to anticipate the particular risks that MCAS presented. On the other hand, there are other roles in the airplane development process where the people involved are expected to have the requisite knowledge to identify and judge such risks, and these are employees of Boeing or the FAA (if it turns out that these roles were farmed out to low-bidding subcontractors, that's a separate issue.) These domain experts ruled that MCAS was acceptable as designed, apparently largely on the mistaken grounds that MCAS failure is just like any other trim runaway excursion, a mistake exacerbated by the failure to properly communicate the increased power of the redesigned MCAS among the domain experts.

No sound root-cause analysis will come to the conclusion that the crashes resulted from Boeing contracting out software testing to low-bid contractors. You are making the fallacy of arguing a general point that does not apply in this specific case.