5 ms·
The fact your friend is suffering no consequences and is able to just carry on is exactly what is wrong with this industry. In a perfect world the creation of
by doesnt_know 1y ago
The fact your friend is suffering no consequences and is able to just carry on is exactly what is wrong with this industry.
In a perfect world the creation of software would have been locked down like other engineering fields, with developers and companies suffering legal consequences for exposing customer information.
- deleted 1y ago[deleted]
- Zopieux 1y agohow dare you stifle innovation with your communist laws, I thought this was America
- woooooo 1y agoThe 80s and 90s devs who built our current software infra were, on average, FAR less credentialed than today's juniors and mids who mostly don't understand what they're building on.
- stouset 1y agoThe difference is we didn’t know any better back then. We do now.
- pishpash 1y agoSurprisingly, 80's and 90's developers were quite skilled low-level developers who knew very well all the ways things could go wrong. The difference was the stakes were not high then. The blast radius was maybe a hundred thousand people and the worst was they lost their own files. Now some AI-controlled process or apparatus could ruin everyone's credit and maybe even kill you and all your neighbors.
- lan321 1y agoThe whole comparison is apples to oranges. Products are massive nowadays and a whole lot more connected.
- cguess 1y agoSure, and Da Vinci didn't have an architectural degree when he was designing bridges, but now you need a proper license to do so. Society learns to do better
- raincole 1y agoPeople really want to bring down the growth of the USA's software industry to EU level.
- randmeerkat 1y ago> People really want to bring down the growth of the USA's software industry to EU level. The EU is the only place hiring software engineers right now. Everyone in the U.S. just keeps laying them off.
- api 1y agoSome of that is US companies hiring in the EU because the salaries are lower. Source: I know of multiple companies, even on the smaller side, doing this.
- guappa 1y agoUSA is bullying europe into buying billions and billions worth of € in weapons and we're supposed to feel sad a couple of your jobs move to europe?
- B-Con 1y agoThat hiring is by US companies moving at US speeds, who greatly eclipse the growth rate of EU companies, which is the point OP was making.
- woooooo 1y agoI think "innovativeness" is massively overrated compared to network effects and consolidation. Spotify is European. Any innovative SV companies going to unseat them with sheer pluckiness? Same goes for Meta or Amazon going the other way. China and to some degree Russia have their own ecosystems due to anti-innovative barriers they put up.
- jjani 1y ago
- api 1y agoIn that world we’d just be transitioning to 32-bit software and still running MS-DOS since it’s certified. Linux would never ever have broken through. Who can trust code developed by open source cowboys? Have we verified all their credentials? There are some industries where the massive cost of this type of lock down — probably innovation at 1/10th the speed at 100X the cost — is needed. Medicine comes to mind. It’s different from software in two ways. One is that the stakes are higher from a human point of view, but the more significant difference is that ordinary users of medicine are usually not competent to judge its efficacy (hence why there’s so much quackery). It has an extreme case of the ignorant customer problem, making it hard for the market to work. The users of software usually can see if it’s working.
- 0xEF 1y agoA reliable, un-bloated OS? Sign me the eff up.
- RogerL 1y agoGo check out VxWorks or the like. only 20K a seat, build tools at a similar price, and then oh joy, runtime licenses required to deploy the sw you wrote. Which are reasonable prices when lives are at risk. Yes, I know RTOS are not general purpose, this is NOT apples to apples, but that is what that kind of reliability, testing, safety certification, etc. costs.
- shakna 1y agoOr QNX for the price of Windows, for a certified UNIX.
- majormajor 1y agoYou, of course, say that like it's a bad thing. I'll say video games would certainly be worse. I don't know if we'd be worse off with a lot of other software and/or public internet sites of 20-to-30 years ago. A lot of people are unhappy with the state of modern consumer software, ad surveillance, etc. Probably a lot less identity theft and credit card/banking fraud. For social media, it depends on if that "regulate things to ensure safety" attitude extends to things like abuse/threats/unsolicited gore or nudes/etc. And advertising surveillance. Would ad tracking be rejected since the device and platform should not be allowed to share all that fingerprinting stuff in the first place, or would it just be "you can track if you check all the data protection boxes" which is not really that much better. I'm sure someone would've spent the time to produce certified Linux versions by now; "Linux with support" has been a business model for decades, and if the alternative is pay MS, pay someone else, or write your own from scratch, there's room in the market. (Somewhere out there there's another counterfactual world where medicine is less regulated and the survivors who haven't been victimized by the resulting problems are talking about how "in that other world we'd still be getting hip replacement surgery instead of regrowing things with gene therapy" or somesuch...)
- atleastoptimal 1y agoLet's say it was coded extremely well, but nevertheless a more advanced exploiter wreaked similar havoc. Would they still be liable in your perfect world? To some degree the principle of caveat emptor should apply in some tiny, nascent business, otherwise only large juggernaut monopolistic incumbents would have the means to have any stake in software.
- Frieren 1y ago> Let's say it was coded extremely well, but nevertheless a more advanced exploiter wreaked similar havoc. A doctor kills a patient because malpractice. Could that patient have died anyway if the patient had a more critical condition? That is a non sequitur argument. > Would they still be liable in your perfect world? Yes. The doctor would be liable because did not meet the minimum quality criteria. In the same way that the developer is liable for not taking into account any risks and providing a deeply flawed product. It is impossible in practice to protect software from all possible attacks as there are attackers with very deep pockets. That does not mean that all security should be scrapped.
- pishpash 1y agoThat's always the double-edged sword with regulation, but sooner or later people will demand it, or much more of it.
- rsynnott 1y agoImagine these two scenarios: Your spouse dies in surgery. The highly experienced surgeon made a mistake, because, realistically, everyone makes mistakes sometimes. Your spouse dies in surgery. The hospital handed a passing five year old a scalpel to see what would happen. There's a clear difference; neither are _great_, but someone's probably going to jail for the second one. In real, regulated professions, no-one's expecting absolute perfection, but you're not allowed to be negligent. Of course, 'software engineer' is (generally) _not_ a real, regulated profession. And vibe-coding idiot 'founder' certainly isn't.
- deleted 1y ago[deleted]
- csomar 1y agoRight. Because the solution to all of this madness is SOC2 compliance or something along those lines. What happened is a perfect natural selection. The friend is a very small actor with probably a dozen customers not a multi-billion $$ company with millions of customers.
- kalaksi 1y agoI don't remember the specifics well, but under GDPR they'd be required to give breach notification to customers, maybe write a report and get audited and possibly get fined depending on the situation. Customers could demand compensation (probably doesn't make sense here).
- conradfr 1y agoWell his customers got a refund, that's nice ;) But I guess the lesson is to vibe code to test the market while factoring a real developer cost upfront and hiring one as soon as the product gets traction.
- __MatrixMan__ 1y agoIn our imperfect world, by the time the government could get together a reasonable certification process the content you're tested on would be out of date. Maybe when the industry is older it'll change slow enough to do that, but I don't think that'll happen so long as there's so much money aimed at disrupting everything and monetising the disruption. Were going in circles far too fast to have licensure that hinges on being up to date.
- gowld 1y agoThat's what tort law is for. It leaves the details to the experts, and judges based on general notions of intent, negligence, and harm caused. The threat of financial ruin should incentivize against selling malware.
- __MatrixMan__ 1y agoHow do you use tort law to keep licensure curriculum up to date?
- TRiG_Ireland 1y agoGDPR fines can accomplish this.
- parliament32 1y ago...and this is where compliance comes in, and is the exact reason real companies won't talk to you unless you have (at minimum) SOC2. There's billions of products out there, how do you know if it's actually good software developed by a team, or some idiot like above vibe-coding slop into what appears to be a functional application? We all make fun of audits and checklist-based-security but it would've almost certainly prevented the above from happening.
- deleted 1y ago[deleted]
- mcv 1y agoImagine vibe coding spreads to civil engineering and people start building bridges this way. Have AI design it and then probably 3D print it on location. > legal consequences for exposing customer information. Still a good idea. Also without taking vibe coding into account. Far too many tech companies are way too sloppy with customer data. Often intentionally so.