I wonder what would happen if devs could say to their boss "no, this won't be released until we're confident in it" with legally enforced immunity to consequences.
I wonder what would happen if devs could say to their boss "no, this won't be released until we're confident in it" with legally enforced immunity to consequences.
You can still effectively do exactly the same job as a licensed engineer without being licensed, you just can't sign off on work (And thus be held responsible).
The way I see it, creating a license for Software Engineers doesn't really fix the issue. It just creates a scapegoat to blame when things go wrong.
That's just how it works for other engineering disciplines; with the license, the scapegoat has the legal power to refuse responsibility until they're confident things won't go wrong.
Even top software companies have things break or go wrong very frequently compared to traditional engineering.
I don't see this as a good solution in the software world.
Hey can you put together this trillion piece jigsaw puzzle? Oh and we need you to sign off on it. You're sure it's not going to kill anyone right?
Works on my machine!
Then you say "no". Business "needs" are important for replaceable serfs with no power to say otherwise; when the business needs engineering sign-off, you tell them what they needs to do.
I don't see anything changing as long as it's in money's interest to stay where it is (money rules this country point blank). Right now it's in too many business's interest not to change. There are also slews of developers earning quite a bit who might be forced into career changes depending on how licensing could be implemented.
When a bridge falls down, building collapses, patients die, people take notice.
Meanwhile, we've had the social insurance numbers and banking history of 165M+ UK, US, and Canadian people leak out of sheer technical negligence [0], and it resulted in a meek settlement and hardly broke through the public consciousness.
It seems to me that until someone dies in a way that is very clearly linked directly to a woefully negligent and under-trained software engineer messing up in a very public way, the needle is not going to budge at all.
Perhaps autonomous cars? Even then I doubt it, to be honest.
So is that the remedy people are recommending here?
Today, it's well under that.
It is, of course, long overdue; Therac25 should have really gotten the effort going, but, ce la vie with a irresponsible economy. It's plausible the EU legal systems will develop this effort first. I would not be surprised to see France or Germany fully develop the idea, probably in connection with Airbus or Siemens. Anyway. Idealism around quality....
If I remember history correctly, there wasn't one boiler explosion that caused us to start regulating who was allowed to design boilers. It's just that as boilers became more and more popular at the end of the 19th century, people started being maimed and killed more often, and at some point we just as a society decided enough was enough.
https://www.vice.com/en_us/article/yw798m/oregon-unconstitut...
Yeah, just what the software industry needs.
I guess I'd argue that those people shouldn't be legally allowed near this kind of thing without that kind of a certification. Looking into all of the other engineering disciplines, that's exactly the kind of thing you see. I have a BSME, but I haven't taken the Fundamentals of Engineering exam to get my FE cert, in part because getting a PE certification requires working underneath a licensed PE for a certain number of years, which isn't the case for my current job.
I also know that by not doing so, there are certain projects that I simply can't work on. I have to imagine that there's a way to create a legally enforceable framework that falls into the same category for software engineers. Want to build a company that creates a digitally-synced notepad? Have at. Want to touch personally-identifiable medical data? Better have a licensed engineer working on that project to sign off, else your company is wide-open to liability claims with teeth. If something unreasonable gets by the signed-off engineer, they're on the hook too.
Obviously, it's a complicated problem, and reducing things to a first-order solution rarely is a catch-all, but there has to be some more professional/personal responsibility taken by the individuals building these systems, and a requirement of licensure is a way of empowering engineers in those positions to the point where it actually matters.
You answer your own question fairly well, but I'd add the observation that in licensed engineering domains, we don't always require licensed engineers. We have a licensing regime for structural engineers, but we don't require them for minor structures like gazebos or doghouses.
We could have licensed Software Engineers, but only require licensed oversight for software dealing with human lives (avionics, medical devices), PII, elections, and a few other critical cases.
I developed software for medical devices and you have to do a risk analysis, formalize the software development process, declare qualifications of people, make it revision proof, have a formal testing process, ... everything is already accounted for.
Notified bodies ensure compliance. They have the problem that they cannot really evaluate the work of software engineers of course. Not even another software engineer could do that within feasible time limits. No software engineer can make sure there aren't exploits that could endanger user data. You can at most test if due diligence was ensured.
The manufacturer is responsible for ensuring safe operations of devices and yes, that includes keeping personal data safe.
But again, the problem wasn't the engineer at all, the problem is the wish for amassing data like this. Paper license or not, it rarely ensures competency and wouldn't have solved this problem.
Aside from legislative issues that ensures that user data belongs to the user the data is about, ensuring that companies don't sell and share medical data with "friends and family", ... this is probably the last step, if it is even required at all, which I would dispute. There are no guarantees if you amass data like it was done here.
I've worked in critical infrastructure work and retain an interest in the field. A professional software engineering license should be legally required for certain classes of risk.
Ultimately the answer to an irresponsible feature ask should be:
> I will not approve implementing this feature, because in my professional training and experience, the risk exceeds the acceptable tolerances for a (spaceflight, medical, power systems) delivery. If I implement this and a failure occurs, I will be in court and my career over: I refuse.
You are willing to pay the costs of "professionalizing" software development and installing expensive gatekeepers, certifications, signoffs, and processes at every step, right?
Most of that is already in play already after about 30 people are in a group, we as an industry haven't formalized it, and there's no legal teeth around it.
We spend about 15k per year for about 10mm in coverage (we are a small shop). This sort of oversight is not just an engineering one but it’s fundamental to the core ops of the business. If we are rushing under client pressure (or just running late) to the extent we take on risk to trigger liability, it’s full stop.
https://cense.ai/about Guy number two here had the background to know better. Just didn’t make it a priority. It’s unfortunate. The only way things change is when we start seeing data warehousing/collection as a liability (not an asset) and manage it accordingly. And making the penalty for error unforgivable.
The irony is, of course, that PL/E&O insurance for software work runs pretty cheap, presumably because liability on the part of developers of software is quite rare!