But no one is going to get fired or held back for choosing those 'enterprise' tools. They've spent a lot of money, everyone has a checklist, and people move on, even if there's a breach. And some jr might have pointed out "hey, this open source toolset does this, but is kept up to date and has found 47 things our scanner didn't find" and this jr will likely be ignored.
It’s maddening.
Maybe there's a clever trick I'm missing here.
Of course any proposal to ever hold a programmer accountable for literally anything is always unpopular on HN, for obvious reasons.
Engineers should only be held accountable for decisions they made personally. The unfortunate reality is that, a terrifying amount of the time, terrible decisions are handed to engineering teams as required implementation details from managers, executives, product directors, etc. So should engineers be held criminally accountable for their product manager demanding MD5 hashes on passwords?
Of course management should also be held accountable, but until engineers are forced to have some skin in the game they will continue to be as pliable as wet noodles.
Consider this: who better to blow the whistle on management than an engineer who knows they've been given an illegal order?
I guess we just fundamentally don't agree on how power dynamics effect these types of scenarios.
Right now, the conversation goes, management: "I want x". Engineer: "X is insecure, we should do y instead". M: "Y will cost us X more than x, and it's never going to matter for us, anyway."
This puts the engineer in a position where they need to argue and justify the cost. Compared to "Sorry, I can't do that; it's illegal and I'd go to jail if I did that and was found out." Now the engineer doesn't have to justify anything. The law isn't a burden on the engineer here, it's a shield.
Yes, there are still some scenarios in which management insists. In my limited experience, that's in gray scenarioa where it's arguable whether the law applies. But the point is, it's much easier for an engineer to argue whether the law applies, than whether it is worth the money.
I think you can see these effects in the lengths companies go to protect healthcare data (hipaa) vs any other random personal data.
The big difference is that companies need professional engineers. Professional approval on certain things is required by law. I'm not sure that would be a good idea for software, but that is what makes the system work for professional engineers.
Presumably there would be repercussions at the government level if a company repeatedly demanded engineers do things worthy of stripping their licenses though, no?
The individual engineer doing the work needs a license, but the company itself also needs a permit to practice. The permit must be held by an engineer, who is personally responsible for the engineering that occurs under their permit.
So, the permit holder needs to worry not just about their own ethical behaviour, but that of all engineers in the company. They are incentivized to ensure the company will hold the public safety paramount, or to walk away if they cannot (thereby leaving the company without a permit).
If the company has a pattern of misbehaviour, it may be difficult to obtain a permit.
So, yes, we agree, if there are repercussions for a company regularly breaking the law, then engineers can and should refuse work that has negative legal or moral repercussions. But in the world of tech, that's not the case.
I personally believe that you, the software developer typing in the code, should hold yourself personally accountable for what you are typing in. You might also be designing what you type in, or even setting the requirements, but it might be other people. Regardless, you are making the software come into being--you're the one coding it and pushing it to the repo, so you should set the standard of what is acceptable. This "well, boss told me to do it!" rationalization and blame-shifting is how we get dangerous and unethical software.
And, yes, I have quit software jobs where I was asked to write software I considered ethically questionable, and failed to change the boss's mind.
No, I am suggesting that there is significantly more grey area between your moral highground and reality.
> I personally believe that you, the software developer typing in the code, should hold yourself personally accountable for what you are typing in
Yep.
> This "well, boss told me to do it!" rationalization and blame-shifting is how we get dangerous and unethical software.
It really is a strange world that, when corporations are attempting to turn profit on illegal behavior, it's the meaningless bodies-in-seats that we're trying to hold accountable.
I am, and have been, repeatedly, suggesting that the lowest level cannot be held accountable without holding the rest of the levels accountable. Jailing engineers for doing things their companies demanded of them is ridiculous if you're not also jailing those doing the demanding. I'm kind of shocked this isn't painfully obvious.
> And, yes, I have quit software jobs where I was asked to write software I considered ethically questionable, and failed to change the boss's mind.
Congratulations, that's a level of privilege lots can't afford.
The equasion should be, for management: "Y will cost us X more than x, but if X is hacked we will get taken to the cleaners"
For the actual engineer to be held responsible you would have to add a formalised approval process, so that its clear who signed what off. Inagine you signed off on something, and then changes were made without your knowledge - that much easier to do with software than a bridge.
What you're asking is for an engineer to be stuck in a place of legal culpability if they do the work, and to be fired if they don't. Added bonus: you mention whistle blowing, but who the hell would they whistle blow to?
If there's a proper industry or governmental group to blow the whistle to, that will also see the engineer financially compensated until such a time as they find a new job, then fine, it's fair to make engineers culpable. Otherwise, you're just making engineers suffer for the bad decisions of those made above them, by making them either legally liable, or risking their jobs.
You're looking to now make it so that there's a punishment levied on the developer, who has no more power to say no than they currently do. You want them to say no, but all you're doing is making it more unpleasant for them to not do so; you've done nothing to make it easier to do so.
Do you think the guy signing off on a bridge or power station design gets pushed around by “product managers” demanding shitty or cheapskate design or construction?
You were arguing that the specs or decisions made above their pay grade forced the software engineers into a dangerously faulty design which they dutifully created and shipped.
Please login
Username: __________
Password: __________
for $5.7M a year is always unpopular in business circles, for obvious reasons.(Not that I can read German to the standard required for understanding laws and looking it up for myself; I can just about manage tabloid newspapers…)
It should still be consistent with registration/login with things getting truncated, but I think this is also the default in PHP if you are using password_hash() today. Is that a security issue?
https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
I don’t think it’s “a default”, it’s a fundamental limitation of the algorithm.
Specific bcrypt libraries could implement length-reduction by default though.