Live data from Hacker News

The Software Industry Is Still the Problem

queue.acm.org

51–60 of 81 posts

Re: The Software Industry Is Still the Problem

#51
post #37

> As I write this on an early July morning, 200-plus corporations, including many retail chains, have inoperative IT because extortionists found a hole in some niche, third-party software product most of us have never heard of. As I write this, millions of cars have gotten stolen due to vulnerable lock mechanism. A thief can with simple toools just open the door, start the car and drive away. Do we sue the engineer d…

Sorry, this analogy does not hold up.

First of all, you're comparing unintended software vulnerabilities to physical locks; being able to open a lock with a lockpick is an element of the design! Everyone knows this going in!

That aside, ask yourself what car manufacturers have to do to prove the safety/security of everything in their supply chain down to nuts and bolts, and what the consequences are when they make a mistake.

Now compare that to how modern consumer software projects do dependency management and verification, and what happens when they have a whoopsie because some open source library they pulled from GitHub with a "no warranty" license exposed them to a critical data breach. In my experience they throw their hands up and say "meh sorry, software is hard."

Re: The Software Industry Is Still the Problem

#52

The other types of engineering the author refers to that are subject to certification involve the physical safety of other people. But still, plenty of software development roles are subject to professional liability, particularly where the work is linked to people’s physical safety. As a contractor or director of a company providing software services, I’ve been required to have professional indemnity and public liab…

I think you might be missing the forest for the trees a bit. Many industries have a very wide range of certifications and there's no reason IT couldn't be the same. For example, think doctors: some are certified for surgery, some are certified to give physiotherapy, some are certified to refer you to other doctors etc. I don't think cost is a reasonable argument either — you wouldn't want a plumber with no knowledge…

There’s more diversity in roles and risks in IT than there is in medicine. But even still there are still jobs related to health that don’t require qualifications and certification - e.g. massage and fitness training.

Plumbing certainly involves physical safety and health; poor plumbing work can damage the building leading to collapse, or cause a fire/explosion, water contamination or electrical faults leading to injuries or fatalities.

Re: The Software Industry Is Still the Problem

#53
post #20

When it comes down to it, most software bugs don't matter. Reimburse the customer, wait a few days for a dev to fix something, whatever, it'll get resolved and everyone will be whole again. Contrast this with construction, if there's a "bug" in the building, people can die, or lose housing, or companies can lose large amounts of money. Bug in a billing system? Just try and pay again next week. In industries where sof…

Yes, it's not an industry problem, it's just that most software isn't critical. When software is critical, it's also handled differently. I worked on critical car software, where a bug is expected to cause a safety hazard, and can lead to a car crash. The development process is completely different from some non-critical web service. FMEA analysis, breaking down the software into ASIL levels per component so some components get the very thorough ISO 26262 procedures, every code change has to be traced to a requirement and reviewed by two people. Tooling requires 100% branch coverage in tests, anything that's manually excluded from tests has to have a written justification and manual analysis. Code to be written strictly in MISRA C, any non-compliance detected by static analysis blocks the merge until resolved or manually verified and documented.

Developing that kind of software is so different from most non-critical software that it might as well be different industries altogether.

Re: The Software Industry Is Still the Problem

#54
A small internal software group like mine would almost certainly be a casualty of any real increase in software liability.

On the other hand, the inevitable slowing of technology change and consolidation of libraries, languages, and frameworks would be kinda nice. Hard won, deep knowledge of technology that is 20 years old would be worthwhile. And I could finally stop yelling at JavaScript frameworks to get off my lawn.

Re: The Software Industry Is Still the Problem

#55
post #38
post #11

Earlier quoted context omitted.

Im not trying to establish a categorical imperative that applies to everything, such as toilets, but may make sense in certain industries (maybe zoological taxidermy)? The larger point is why the software industry has avoided regulatory capture or eschews certification in contrast to other markets. In other words, more boadly, is it the government that pushes for these laws, or the market that demands/asks for them?…

> The larger point is why rhe software industry has avoided regulatory capture I would argue that the software industry is not run by software developers but by the cowboys in suits at the Excel and Powerpoint rodeo in the boardroom. It's rife with regulatory capture, but software developers in that environment are considered a liability to be minimized. Tweaking that expense line in your presentation to the sharehol…

I'm tring to highlight and draw comparisons _between_ industries in order to discover what is _different_ between them.

I don't think the claim that software devs are oppressed by management (as if other industries do not have management) and would run things better themselves (they wouldn't) sheds any light on discovering those differences.

Re: The Software Industry Is Still the Problem

#56

Oh look. An institution who’d be the first to sell certifications wants to make certifications mandatory. Nah, thanks. At least I’m Software one can still innovate without having to cut through miles of red tape.

You're also free to build your own furniture even though there are regulations on structures. A structure is both life-threatening when it fails and will almost inevitably end up in the hands of someone who wasn't the original builder at some point in its life.

I should always be free to write software to run my model trains, or even somoene else's model trains however I choose. Making the same argument for real trains (which already have lots of regulation) is much harder.

That said, if licensing did happen, there would definitely need to be tiers. Building software in-house is different than one being sold (saas or on-premise). Regulated industries would each end up with their own licenses, probably.

That said, I go back and forth on this. Something as bureaucratic as licensing doesn't seem like a great solution, but the industry is definitely lacking something. I'm not quite sure what that something is exactly. Maybe we need a split between engineering and labor, similar to construction. Liscenced engineers design and inspect the bridge, unlicensed labor builds it. Similarly, I can usually build small structures without a license, small non-life-critical projects wouldn't need liscenced engineers either.

Re: The Software Industry Is Still the Problem

#57
post #20

When it comes down to it, most software bugs don't matter. Reimburse the customer, wait a few days for a dev to fix something, whatever, it'll get resolved and everyone will be whole again. Contrast this with construction, if there's a "bug" in the building, people can die, or lose housing, or companies can lose large amounts of money. Bug in a billing system? Just try and pay again next week. In industries where sof…

Yes, it's not an industry problem, it's just that most software isn't critical. When software is critical, it's also handled differently. I worked on critical car software, where a bug is expected to cause a safety hazard, and can lead to a car crash. The development process is completely different from some non-critical web service. FMEA analysis, breaking down the software into ASIL levels per component so some com…

The article claims is that stability on a national level involves a large number of these non-critical systems all working correctly on a systemic level.

Re: The Software Industry Is Still the Problem

#58

What is the equivalent of open source software in the physical engineering world that this author respects so much? How is it regulated? If there isn’t such an example, then perhaps software is a category of its own and thus its problems can’t be solved by legacy regulatory tooling.

Model engineering (e.g. live steam) Woodworking? Small carpentry (e.g. non-critical structures, swings, playhouses, most decks (I think these usually require inspection, but not a liscence to actually build), chicken coops? I think in most places you can still build your own house, but it requires inspections.

Re: The Software Industry Is Still the Problem

#59
Licensing computer engineer and scientist - I was wondering when this idea would surface. I mean, that is a great way to strengthen monopolies and consolidate existing players. I didn't expect such a suggestion would come from a Freebsd core developer.

Licensing is about compliance. It helps better control who has access to a certain set of skills, and who can make a living off such skills.

License could require you to be certified for certain technologies, which mean whoever has the best lobbying power win (Hint, it's not Freebsd). It's a great way to keep market shares for specific interests. Not sure how this is good for the industry.

Licensing means you can put barriers to entry for specific demographics (ineligible if born in a specific country...)

Licensing means you can create an entire business model just around licensing fees and licensing bodies, which usually mean some people are left off the game.

You want to increase professional liability and overall responsibility, they are other ways.

First, you have certifications. They already exist and can give ad-hoc solutions for some specific niches, and is the closest that we have to a license today. You can create a mechanism for someone to lose their certification if they commit a professional fault (even if this would totally be used in some case for internal politics and pressuring people in doing they don't want, irrelevant of any actual professional issues).

Second, you have transparency. Company can publish internal explanations of any disaster and if people are terminated because of it, they can make this public. Not that I like the idea... but it is a middle ground - where others are given an opportunity to decide if they to take the risk hire people with public failures, while not removing someone from exercising one's profession because some project went to hell and someone made mistakes.

Anyway, overall, I get his point that he want more responsible engineers on the job, but gatekeeping an industry with licensing sounds like a recipe for an even worse shit show.

Re: The Software Industry Is Still the Problem

#60
post #57

Earlier quoted context omitted.

Yes, it's not an industry problem, it's just that most software isn't critical. When software is critical, it's also handled differently. I worked on critical car software, where a bug is expected to cause a safety hazard, and can lead to a car crash. The development process is completely different from some non-critical web service. FMEA analysis, breaking down the software into ASIL levels per component so some com…

The article claims is that stability on a national level involves a large number of these non-critical systems all working correctly on a systemic level.

well that's true not just for software. For society has a whole to work, you need a bunch of non-critical system to work well together. It doesn't mean you are required to have a license to be alive (However, that would make a great plot for a Black Mirror episode I guess)
Post reply on HN