UK court clears post office staff convicted due to ‘corrupt data’
theguardian.com
theguardian.com
It's like a murderer giving evidence against a random stranger and being believed at face value because they provided all the evidence first hand.
Of course, the CPS (Crown Prosecution Service) has always had the right to take over and discontinue a private prosecution.
[0]https://www.theguardian.com/world/2021/jan/28/rspca-plans-to...
I said this is just like if the police where investigating your for murder and I was told ah well in the bad old days people used to fall down stairs on occasion
https://www.schneier.com/blog/archives/2018/04/securing_elec...
Oh, and also the bit about spending 2 decades covering everything up and trying to clamp down on the investigation rather than admitting you got it wrong, once again at the expense the subpostmasters..
We do the same thing with breathalyzers in most of the US. No independent people allowed to inspect the system for bugs.
The trouble is that if you speak up about it, people ask: "why are you defending drunk drivers?" It's like innocent until proven guilty flies out the window.
But hey, I'm just a stupid peon, so what do I know.
Here's another dangerous idea: the justice system has false positive rates.
A judgement is a test with two possible results: innocent or guilty. Every test has false positives and false negativies. For every judge, there is a chance they'll condemn the innocent or absolve the guilty. How likely is it? We'll never know.
From my personal experience, it seemed like everyone I dealt with who was part if the system was either incompetent, made mistakes, or might have even been covering things up. The trooper I already mentioned. The corporal investigating him said the trooper's lie was just a misunderstanding, but offered no reasoning or evidence to support that. He also overlooked some other things that were violations of policy (they only cited him for one reg when he fit several). The Sargent who approved the citation said he couldn't do anything about it even if it's incorrect, which is wrong because he can take action based on what the LT told me later. The LT investigated a follow up complaint (the trooper never took the corrective actions listed in first complaint). He didn't follow the correct complaint procedures since he closed the complaint without any notes or findings. I had to call IA, then I assume IA called him since the LT called me a day or two later. He can't even answer basic questions like what laws he used to determine the rules of criminal procedure weren't broken and if he investigated the trooper's conduct as prosecutorial misconduct since he acted as the prosecution and knowingly held an incorrect charge and made several misstatements in court (that we have evidence for). The first magistrate we got gave a continuance. He was arrested on unrelated charges. The second magistrate gave another continuance and thought that we were calling him prejudice when asking to dismiss with prejudice (most magistrates in my state are not lawyers). The third magistrate was a retired police cheif who showed bias, wouldn't let us present a motion, misapplied the law, and was yelling at us to the point his face turned red and he was not understandable due to a lack of air. The ADA originally assigned to the case had an email complaint and the information to confirm that the trooper knew this was an incorrect charge and that the citation didn't even claim the elements of the offense were met, yet they took no action and allowed us to be subjected to those pretrial restrictions. At the appeal, the new ADA tried to misapply the law, with some success. They also told the court administrator/scheduling not to talk to us and not to accommodate any of our witnesses without their approval, which normal for other types of cases with standard discovery procedures, but those don't apply here. The judge actually contradicted his himself in some of his reasons for his determinations - at one point saying a trial de novo is a complete do-over so he won't allow any record from that trial to be used and later saying you would need a record of the previous trial in order to have the charge dismissed. He then misapplied the law and would not even look at, or accept as evidence, an official letter from a state agency that helps define an ambiguous term in the law, which would show us to be in compliance with the law. Even without the letter, the principle of lenity and the rules of statutory construction were blatantly ignored. There were also some paperwork and administrative mishaps, like some information not being recorded and later spending 30 minutes on a moot motion, or the court refusing to provide us with the amended citation with the new charge because "we don't have anything to give you" eventhough it's in the file. The other party was in violation of two similar laws the this one, yet the trooper and DA office decided not to investigate/prosecute even when she admitted being in violation for one offense. So much for the law applying equally.
So yeah, in my view the system has no integrity and is severely broken. I have little faith in justice actually being carried out. I guarantee many people have been convicted who were innocent. I think it's mostly due to the fact that innocent until proven guilty doesn't exist anymore.
Honestly, this is now the public perception (and the system) operates these days. I had a trooper recently hold a charge that he knew was incorrect and it carried with it pretrial restrictions that no other charge would. The state police say there's nothing wrong with subjecting people to pretrial restrictions under charges that they know to be incorrect. The attitude is "screw you, criminal" (just a summary offense).
Some states actually get it right and use blood tests. That means that some blood is saved if the defense wants to have it tested (evidence preservation).
Once upon a time, computer programming attempted to be a profession. Fortunately for all of us who write code for a living, we no longer have to live under the threat of that responsibility.
Computer says no = okay it’s your fault.
It’s the equivalent of ‘works on my local’ so get lost you deal with it.
Computers may be binary but the people who make them aren’t.
This failing of understanding and with the advent of easy ML will only add to the problem.
Askimov’s multivac would end the human race before it helped it.
Applications are starting to get to the point of dogma for many of us at a certain level.
Still love the film ‘Idiocracy’ becoming more and more prescient.
Part of which was caused the very "antagonistic" IB or SD like the US postal Inspectors.
There was a bit guilty by suspicion tendency that went on and I suspect some of this culture was embedded in the organisation.
Certainly having yourself or your staff investigated by SD was considered very stressful even after the "bad old days"
BT = British Telecom. British telco, which used to be part of the government-owned Post Office, but was separated from it in 1981 and then privatised in 1984. The delivery services part of the Post Office (Royal Mail) was separately privatised in 2013; but the retail post office business (Post Office Ltd) remains under full government ownership, albeit most of the individual post offices are privately run by franchisees – and it was these franchisees who were being prosecuted
IB = Investigation Branch – https://www.postalmuseum.org/blog/the-post-office-investigat...
SD = Security Division
Blame whoever signed off on the system. Can't fix bugs that aren't reported.
https://freedom-to-tinker.com/2009/05/11/breathalyzer-source...
https://lawreader.com/?p=12801
https://www.tradesecretslaw.com/2008/02/articles/practice-pr...
https://arstechnica.com/tech-policy/2009/05/buggy-breathalyz...
https://www.nytimes.com/2020/06/24/technology/facial-recogni...
The security photo is directly viewable by the police and the accused.
No doubt it's some sprawling, insane Java monstrosity Manhattan project or suchlike.
"Yeah - 10,000 classes - completely fine and not crazy at all."
If their system were up to date, written in a safe language, has unit tests and an independant review said it was solid, then it is just one acceptable piece of evidence.
What i dont get is - where was the money? Supposedly hundreds of people stoke huge amount of money, and none of them had it in a bank, bought a new car, or showed any signs of suddenly becoming wealthier. Where did the judge think the money go to, they ate it? How was this not suspicious?
I personally think this is partly down to the fact people don't get state defence lawyers anymore in the uk. You could accuse me of fraud with zero evidence and I likely would have to plead guilty as I don't have 20k for the down payment for a lawyer...
What a shit storm. Now watch as nothing changes...
https://en.wikipedia.org/wiki/Formal_methods
We should consider the cost of QA and of engineering process against the cost to these 39 people of their freedom and a large part of their lives due to an accounting error in the software.
The places where you do see formal-methods would be in, for example, FADEC for aircraft engines, or an operating system process scheduler.
As it is, I don't know what part of the system is responsible for reporting money stolen by postmasters - the BBC News article is light on technical details. The Register has more details: https://www.theregister.com/2021/04/23/post_office_scandal_f... as does this website focused entirely on the trial: https://www.postofficetrial.com/2019_03_25_archive.html
The bugs are described as being part of the systems' payments processing system (as the Post Office does function as a financial institution, after-all) - but that at least some of the bugs were caused by ad-hoc work on the system (wot, no CI/CD to gatekeep releases?!) so I'm thinking this is just institutional incompetence - let alone a lack of software-engineering processes - so the idea of them implementing formal-methods for proving the system's correctness is laughable.
[1] https://www.judiciary.uk/wp-content/uploads/2019/12/bates-v-...
Imagine not doing inspections of new building construction because it would be costly.
No, the problem is greater than that. Decisions that affect people should not be made solely by computers or algorithms, and those decisions should be made transparent and auditable. If that leads to different/better ways of writing software, good. It's a larger societal issue though.
I think there's a lot of room for writing software better, including expanded source access for public systems and formal verification when critical.
But the failure in this case isn't technical, it's legal. It's rational to decide that occasional bugs in a mail software system are acceptable, and not worth the cost of designing a system's development around formal-verification. What's obviously insane is treating such a system as if it's bug-free beyond a reasonable doubt, and ruining innocent people's lives over it.
There are a lot of forms of gross incompetence and negligence that we're all fine with because they're so common. Failing to reason about software systems and their pitfalls, or consult with those who are capable of doing so, is an extremely-common and often-dangerous example (cf dumbass Senators grilling Zuckerberg with their 1970s understanding of how technology functions).
The blame here lies squarely on the prosecutors, judges, etc who are responsible for these verdicts. They should be ashamed of themselves.
Q) Did you or any of the people you got to examine the software found any way that what the defendents said was true?
A) No
Q) Then you are guilty beyond reasonable doubt.
I think the bigger issue here is around the power that a large organisation wields to duck and dive and use corporate tricks to manipulate how it played out. For example, the fact that so many people had been accused could have been analyzed if it was known e.g. Last year 5 convictions, this year, 700!
If you're going to convict someone of stealing £59,000, the very first thing you should have to show is that £59,000 actually got stolen. If there is reasonable doubt that the crime took place, no one can be guilty beyond that reasonable doubt. If the defendant claims the computer system got it wrong, it's not enough to say you are unaware of bugs, the prosecution should have to show that the computer's output was consistent with the results of doing the calculation by another method.
Can only speak for English and Welsh law, but this isn't accurate. Theft is prosecuted under the Theft Act 1968 and does not require the accused to actually receive the goods or money stolen. All the accused need do to "appropriate" property is assume the rights of the owner e.g, if the accused had access to someone's bank account and they sent money to a third-party, that's still theft because they assumed the rights of the owner (to transfer the money) even though the money didn't go to the accused themselves.
Yes, if they could have proved they also received what was stolen, that would have been a slam dunk but there are enough plausible reasons why they can't find the money. Maybe it was given to friends and family as cash, maybe it was used to gamble or to pay off some criminal.
It isn't much different than somebody saying, "you did it because we found your DNA". The Courts or Jury are inclined to believe it because "science" and if the defence are not on their game enough to show how "because DNA" is not always watertight, the defendent is seen as guilty beyond reasonbale doubt.
No, it claimed that what they had sold didn't tally, a claim they never proved. The defense put forward another plausible explanation - that the software was incorrect, and the prosecution obviously didn't prove the software was accurate.
Even if the computer was right and there was a genuine discrepancy in the tally, you then need to prove that this person was the one responsible for it. Certainly in this case, there couldn't possibly have been sufficient evidence to prove they were the ones that did it if it was never done to begin with. Absence of evidence isn't evidence of absence, but it sure as hell isn't proof of presence.
In the "we found your DNA" analogy, you're finding my DNA in my workplace where nothing has actually gone missing - how does that prove I am guilty of theft?
If this was one or two cases, then sure, maybe they were really smart about hiding the money. However, there were hundreds of convictions. What is the more likely explanation?
Post office looses packages all the time, should someone go to jail for that too?
If their stuff doesn't tally, they are disorganised, they loose stuff or have idiots. Thats their problem. Maybe it's post office employees stealing shit.
Why do we immediately assume postmasters have abything to do with it without a shred of evidence?
There is a strange presumption in here. It is true that lack of evidence doesn't always means there's evidence that there was no crime. But that shouldn't matter. A crime should only be prosecutable if it is demonstrable. We shouldn't say "oh, well the prosecution had a really hard case, we should just convict this person anyway because it wasn't fair to those lawyers." That's such a perverse way of reasoning about it.
Glad to see them finally have their names cleared, and can only hope prosecutions will follow as a result, utterly shameful how the Post Office, Fujitsu and others behaved. For example:
> A Fujitsu programmer from the time, Richard Roll, who would become a key witness in the sub-postmasters’ high court case against the Post Office in 2019, told the Eye that Horizon was one the company’s few profitable contracts. Among other private sector deals, it was also lining up a key role in the mother of all government IT splurges, New Labour’s £12bn NHS IT project (Eyes passim ad nauseam). Fujitsu could ill-afford either bad publicity or the penalties that came with software faults. “We would have been fined,” said Roll, who worked at the company between 2001 and 2004. “So the incentive was to pretend it [software error] didn’t happen”, while running “a constant rolling programme of patches to fix the bugs”. Fujitsu “would basically tell the Post Office what they wanted to hear”. So prolific did Roll’s bug-fixing team become it won the company’s President’s Award for outstanding corporate contribution in 2002. And the quick-fix, ask-no-questions approach that suited Fujitsu financially enabled the Post Office to hold the line that blame for all branch shortfalls must lie with the sub-postmaster.The Fujitsu insider concluded that errors leaving sub-postmasters out of pocket were inevitable. Could that mean hundreds of them? “Given there were [about] 20,000 post offices when I was at Fujitsu and the sort of problems we were dealing with all the time, yeah,” he told the Eye. “Sounds reasonable.”
>For the first 10 years of Horizon’s existence, transaction and account data was stored on terminals in each branch before being uploaded to a central database via ISDN. Our source says this part of the system simply did not work.
>“The cash account was a piece of software that sat on the counter NT box, asleep all day,” he said. “At the end of the day, or a particular point in the day, it came to life, and it ran through the message store from the point it last finished. It started at a watermark from yesterday and combed through every transaction in the message store, up until the next watermark.
>“A lot of the messages in there were nonsense, because there was no data dictionary, there was no API that enforced message integrity. The contents of the message were freehand, you could write whatever you wanted in the code, and everybody did it differently. And then, when you came back three weeks later, you could write it differently again.”
And down further
>Speaking to Computer Weekly in 2015, the anonymous source told us: “The asynchronous system did not communicate in real time, but does so using a series of messages that are stored and forwarded, when the network connection is available. This means that messages to and from the centre may trip over each other. It is perfectly possible that, if not treated properly, messages from the centre may overwrite data held locally.”
>Four years later, former Fujitsu engineer Richard Roll wrote in a witness statement to the High Court: “The issues with coding in the Horizon system were extensive. Furthermore, the coding issues impacted on transaction data and caused financial discrepancies on the Horizon system at branch level.”
BUT the most important part
>So far, nobody at the Post Office or Fujitsu has been held accountable
The most important part is that the PO used these actions to claw back "stolen" money from its postmasters. This money appears to have ended up in its profit and loss account.
If true this means that instead of the postmasters stealing from the PO, the PO was stealing from its postmasters.
There's been at least one claim - in the Daily Telegraph, so questionably credible, but never mind - that a document exists proving that senior management were aware that the accusations against postmasters were untrue, but carried on regardless.
If that document exists it changes the narrative from accidental tech failure and management incomprehension to something less wholesome.
Jail sentences, bankruptcy and suicide has been caused, management that oversaw this need to face prosecution.
This is what happens when you outsource core financial systems to low cost bidders with dubious tech chops building a message queue system is not fraking rocket science at this point.
Back when I worked on the ground up billing system for Telecom Gold (aka Dialcom) we did this as the existing mish mash of dodgy code that Dialcom offered (Sorry Eric) was not up to standard.
We had large amounts of internal auditing built in and we tracked discrepancies to the Penny.
The CEO blames one of their directors; the Director blames the supplier; the supplier blames the requirements documentation; the Business Analysts blame the culture for creating confusing and conflicting requirements.
Yes, you can hold the organisation accountable but then the people who worked there back then are long gone, they don't care if the Post Office gets fined £500M.
You only have to look at the enquiry into the flammable cladding scandal which was entirely down to fraud, yet, there are people who have not been arrested over their misrepresentation of their products.
Exactly which specific problem is "holding corporates accountable" trying to fix?
If it's that postmasters were being falsely convicted, then the way to fix that is to raise the burden of proof significantly. I hope this case has done that, and next time a court will not accept "computer says so".
With that fixed, the corporates would have to take the (falsely reported) losses; they wouldn't be able to pass it on to the postmasters like they did. Then the consequences of the problem will remain with the people responsible.
Is that sufficient?
The problem is that it is possible to design malicious systems which through incentives, ensure that illegal acts will take place, yet only low-level actors are ever punished. The people who architected the systems and made the decisions statistically guaranteeing illegal activity escape punishment through plausible deniability and abscond with their ill-gotten gains.
Besides this scandal, see the failure to punish any executives after the 2007 crash, or Carrie Tolstedt and John Stumpf of Wells Fargo who even after clawbacks retired tens of millions of dollars ahead, etc.
The individuals need to be held accountable and do jail time. "Just doing my job" is literally not an excuse for breaking the law!
Everyone who knowingly covered this up at least committed fraud and/or perjury, or were accessories to fraud or encouraged or even financially remunerated people to perjure themselves(lower level people getting promoted for lying in court).
Their perjury led the government(in the name of us, UK citizens) into immorally, if not illegally, depriving other citizens of their liberty and money. If the legal framework to punish this as fraud does not exist, create it. If someone knowingly and with premeditation lies to the government and gets other people in trouble, they should get back that trouble sufficiently ramped up to act as deterrent. 10x 100x the fine, fine as percentage of lifetime net-worth whatever. If people knowingly and REPEATEDLY get people thrown into jail, all those people should be doing the amount of jail time they fraudulently inflicted on innocents. If the problem is the organized plausible deniability nature of the crime, I'm sure there's some racketeering or organized crime laws that are applicable. This whole thing literally became an organized crime organisation.
The CEO(s) at the time are the chief persons responsible.
If there are no consequences for harm, more harm will be caused. By not punishing wrong-doers and shortcut takers you ensure that more wrong-doers and shortcut takers will rise to positions of power, because they are able to outcompete ethical players.
White collar crime is literally destroying modern western society, if not in fact(though I believe in fact as well) then at least by ruining popular perception of our (necessary for a society to function) elites. We need to clean house.
There's a big missing culture of fixing problems in corporations. Which of course must start with acknowledging the problem. Which of course means that people reporting problems shouldn't face negative consequences. Which means that the current cultural gap is not just a nice empty void, it's an actively hostile roiling psychological chasm of corporate warfare.
So if random CEO knew about some problems that actively harmed the employees and did nothing, and later a court says that the company did wrong, the CEO automatically has to pay some fines too.
And it should be possible to share (but not completely delegate) this responsibility down the corporate hierarchy, to incentivize executives/VPs/managers/team-leads to do the right thing.
Of course this would need a political culture that is motivated to develop, fine-tune and enforce such a framework. ¯\_(ツ)_/¯
what if the ceo was responsible, but was working under the managers "for them" what if managers worked at the same level as thier team whos role is to make the team productive and support them (or even the team could fire thier manager) etc etc
i wonder if disassociating those two (responsiiblity/hierarchy) might be a step towards fixing these kinds of issues...
[1] https://en.wikipedia.org/wiki/Servant_leadership#History
> even the team could fire their manager
This would likely help a lot with the Peter Pans who ended up promoted to managers but are terrible at managing.
The issue lies with leadership. Start with CEO for creating a culture where safety and quality is ignored. Go down the chain only if there is considerable proof that someone under them ignored corporate orders and delivered buggy software.
ref: https://www.ingenia.org.uk/Ingenia/Articles/c05470e5-337f-4b...
Maybe the FCC went all NYPD-World-Police on the UK - popped over there to run things for a while.
Seems like the Futisu team running Horizon decided to reinvent everything badly.
Much of government IT was being given to consultancies like Fujitsu/EDS in the 15 years since 1994. These contracts ended badly: https://www.computerweekly.com/news/1280096810/Why-did-EDS-c... especially for the public paying the bills.
Martha Lane Fox and the GDS pointed out the folly of this approach in 2010 https://gds.blog.gov.uk/story-2010/
They've done an amazing job overall, but hubris overcame them with things like Verify https://www.google.com/amp/s/www.computerweekly.com/news/252...
This highlights a key part of systems design. A key question you should be asking is: what happens when this fails? Note that's "when" not "if".
So something like Horizon should be used to flag cases for reviews. If a branch is found ot have a cash shortfall suggesting possible theft then there has to be a reconciliation possible to identify if the computer system was wrong.
Bugs happen too. How do they ever have confidence in the system and fix bugs if they can't determine if a given flag is a false or true positive?
But instead the system's output was taken as gospel with no possibility of verification. I'm of the belief that if you can't verify anything the system outputs, particularly for something in a discipline so used to verification as a concept, then that signal is worthless. The fact that convictions happened as a result of this is a crime. This is the UK and not the US so sadly that compensation will probably be limited to nonexistent.
As an aside, this is exactly why electronic voting should be outlawed. You need paper ballots (that can be counted electronically) as a verification measure. And the fact that we even have to debate that makes me sad.
Nationally regulated, sure. Verified with a physical copy (or a different system), sure. But banned altogether? You might as well ban everything in the world that is digital, as none of them are fool-proof.
Voting isn't even that important. The wrong guy gets picked, what happens? Same bullshit as if the right guy got picked. If your choices are "Hitler" or "Jesus", then your system is just fucked up, and making voting fool-proof isn't the way to fix it.
In addition, electronic voting would be a boon to democracy. It would provide another avenue for maligned minorities in remote areas be able to vote, when things like paper ballot voting in the middle of a pandemic might fail or be error-prone (esp. when a fascist fucks with the postal system), or local authorities enforce racist requirements like a physical ID card.
Likewise, if you use a pen or pencil to fill out a ballot that then is counted electronically, that too is fine.
In both cases there's a paper ballot as a source of truth and that's what's key.
If voting is unimportant, why do you care about racist requirements for physical ID cards? Perhaps there might be some sort of connexion between the two!
I don't think we take software reliability seriously enough, most of our focus is on speed of release, ever quicker cycles and it being OK to break things. This culture ruined these peoples lives. Things must change. This isn't a unique issue to Fujitsu it is something most of the software industry is doing, this story could be about just about any piece of software.
Damn straight. I'm really big on software Quality. It's kind of my driving passion.
It has been my experience, that an attitude of Quality is actively discouraged in today's "rush to a crappy, lashed-together-with-baling-wire-and-bandaids MVP" SV culture.
We glorify and make heroes of those that deliberately publish garbage, but make money doing so.
When we look to an industry to police itself; it never does. But the rules and regulations applied from non-domain-expert politicians are often ineffective, burdensome, and really only apply to a bygone era (See ISO 9001/CMMI).
I can see the point of such models in certain areas, like military, aerospace, naval, or, to stay on topic, Horizon, where dev is outsourced, somewhat critical, specs rather set in stone, and non experts need to measure how capable an organization is to deliver, but for anything else it just feels like unnecessary meta-management that brings significant organisational and development overhead.
The single biggest issue with software development, is that it is incredibly dynamic.
Static solutions don't work, and CMMI is a very static solution. Sadly, a lot of quality practices are static.
Dynamic solutions are really difficult to get right, and tend to depend on a lot of hard-to-quantify variables, like the experience and talents of individuals on a team.
For example, I am quite good at designing fairly complex systems, as long as I am doing it alone. I can hold some fairly ambitious designs in my head; which allows me a great deal of flexibility. I can start with a fairly "fuzzy" architectural model (I call it my "napkin sketch"), and begin a project fairly quickly. As the project progresses, I can apply some massive structural changes, and pivot fairly easily.
However, the minute I need to communicate this plan, the whole shooting match comes to a screeching halt.
Team overhead is a really big deal, and I believe it is seldom factored into our plans, in any kind of realistic manner.
AI is gonna pour rocket fuel on this stuff. There's already a great deal of talk about replacing lawyers with AI.
We have some marvelous CI/D tools at hand, but the execs are the ones that push to release before ripe, and they won't let things like auto-test failures get in the way of MVP.
There was a comment here, some time ago, that was made by someone that proclaimed themselves to have started and successfully exited a number of companies. It went something like "If you do not get physically sick, looking at the code in your MVP, you are spending too much time, worried about code quality."
I think that's a pretty good summary of today's startup zeitgeist.
I think that as soon as we say "zeitgeist" we're abandoning all attempts at understanding the full picture. There are huge numbers of tests being written all over the place, particularly with modern software tooling. It's the older stuff (e.g. Oracle Forms) or low code stuff (e.g. Bubble, Dynamics) that are hard to test where the biggest issues crop up, IME, as those technologies will be picked by people who don't value testing.
The one thing I miss are ICEs (In-Circuit Emulators). Those were badass, but processors are so massive, and so fast, that a real ICE would probably cost a couple of million dollars, and be out of date by the time it hit the market.
Tech can't fix bad managers, and money is like Miracle-Gro™ for bad management, if it incentivizes rotten quality.
Obligatory MonkeyUser: https://www.monkeyuser.com/2021/introduction/
The most important bug is that the software doesn't solve the problem that you have. It doesn't matter how reliably it doesn't solve your problem
And we should add:
Unless we can't do so without introducing any additional problems, while solving that problem in a manner that truly solves it; as opposed to making it appear solved.
We really are often best off, with the problem, if the cure is worse than the disease.
When I was younger, we had a saying:
To err is human, but it takes a computer to really fuck things up.
Software doesn't exist in a vacuum and software will never be perfect. Trying to solve systematic problems by holding one part to impossible standards will just make things worse rather than better.
It will be like USSR except more unpredictable because it can come from any direction
A couple of insensitive Facebook posts gets you dropped from consideration for a job... no matter how long ago and how much you may have matured in the meantime.
Google implements FLoC and cohorts start identifying political leanings, medical conditions, mental health issues, anything that's legally potentially discrimination territory... how do you know that someone deduced a cohort topic and denied you <something> based on that...
Tip of the iceberg. Data aggregators already have opaque records on probably everybody alive, just find the one with data about your person of interest.
This needs to be a complete change of awareness and ethics and global law... otherwise we're going to have the movie "The Circle" come completely true as opposed to being just around the corner.
This drives me up the walls. At my last job (food ordering startup the CEO had the attitude that releasing code that was 95% functional was Okay, remaining issues could be fixed as we went along.
As a result, one developer overlooked a bug that cost the company €300,000, loyalty discounts weren't being deducted from payments to take-aways. They then had the cheek to demand take-aways pay them back.
Then they launched a major upgrade to the system at 5pm on a Friday - two hours before their busiest time of the week. It collapsed a few hours later and it was impossible to roll back because they didn't include a roll-back SQL script for the DB. It took till the following Tuesday to fix it.
The DB schema was all over the place and as a result it was slow. Entity Framework couldn't handle it and the SQL it was generating was terrible. Me being the only one with decent SQL knowledge had to replace all the bad EF queries with raw inline SQL.
Despite this, they still carried on deploying without a care in the world. I was told to stop moaning about QA. We didn't have QA or testing staff, the CEOs attitude being why pay for QA staff when our clients will do it for free?
Bob Martin talks about it a lot, how the software developers of the world need to have an "oath", like the hippocratic oath. Two posts that summarize things well (but there might be more where he talks about these things) https://blog.cleancoder.com/uncle-bob/2011/01/17/software-cr... https://blog.cleancoder.com/uncle-bob/2015/11/18/TheProgramm...
Moreover it’s not even clear this particular work even fall under traditional definitions that would required a licensed engineer as those deal with public safety (bridge construction, buildings, etc) and something like this doesn’t really. We’d need an updated definition that takes into account the software needs of the world (privacy and security, etc).
More importantly, the employers of software engineers must have ZERO option to emply a software engineer (anywhere on earth) that doesn't have the same oath.
Doctors have a monospony on their services that makes their oath work: the hospital manager cannot just go hire un-oathed doctors.
Never going to happen in software. Ever.
The phrase "move fast and break things" should be seen as cautionary, not aspirational.
The issue is very often related to massively complex corporate requirements (the Post Office makes me cringe, even today, with the complexity of their postal system) and then coupled with the ever-present need to keep costs low, especially when designing something so complex.
I doubt anyone building this thought it would be OK to break things!
I cannot imagine how it must have felt being under the boot of an entire government and it’s corporate partners due to a bug. This is why we are important. A poorly managed IT system with bad incentives puts lives in danger. It is a literal threat to the safety of society. This cannot be stressed enough.
and
'Justice' is only used ironically now.
I think people see a false dichotomy between making things quickly and making them safe. The fact is in the development of any complex thing, you're going to have bugs, and generally that's okay. But things should be designed to fail safe. Making something that throws errors when something unexpected happens is actually faster and easier than trying (and possibly failing) to handle edge cases; had Fujistu taken that simpler, easier approach then all this pain and suffering would have been avoided.
The key is how we respond when the software fails. The https://en.wikipedia.org/wiki/Therac-25 case shows an example of what not to do - when hospitals started reporting their machines giving lethal radiation doses to people, the manufacturer doubled down on the computers-are-infallible rhetoric, where they should have put every last effort into investigating. Likewise, the post office should have noticed that a rather excessive number of postmasters were apparently fiddling the books, and investigated. Instead, after it was fairly obvious that the computer was wrong, they pushed the computers-are-infallible line right through the courts, and that is what earned them the "affront to justice" judgment.
I agree, but if the first step to solving a problem is understanding that it exists then the first principle here must be to acknowledge that software systems are fallible and therefore any surprising or reasonably contested result they produce should be treated with proper caution until further information can be gathered.
So many of the problems we see when modern technology goes wrong start with assuming it didn't. At that point, it's not even about how you respond to the failure, because you're denying that the failure ever happened. Big software companies with considerable lobbying power seem to be particularly good at convincing people who aren't technical experts, including most politicians, judges, juries and reporters, that this is the case.
A corollary to this is that we desperately need more technological awareness among our politicians, lawyers, journalists and other relevant professions. Tech has become too big to be a minor issue you delegate to some random advisor in a basement office. It affects almost everything we do today, sometimes profoundly, and failing to understand that will inevitably lead to some horrible outcomes as we've seen all too vividly today.
Some would say it's impossible to build a secure electronic voting system, even if your supplier and their employees were completely trustworthy because between physical tampering, state-level adversaries, the state of the art in software development and the impossibility of proving a negative, such security has never been seen before.
In other words, that it's an unsolvable technical problem.
Others would say it's impossible to build a secure electronic voting system even if we were capable of creating flawless bug-free and tamper-proof software and hardware because the supplier will always be able to introduce undetectable bugs if they want to, and no supplier can ever be perfectly trustworthy.
In other words, that it's an unsolvable social problem.
It doesn't matter whether voting machines are actually secure, they probably mostly are right now, but whether a layperson can have faith in the system.
Paper voting is very secure if you involve people from opposing parties in the process and attacks are not very scalable. Most people can think of and understand mitigations for certain kinds of attacks. And if paper voting is too expensive for your country, you have bigger issues. [2]
[1] https://www.youtube.com/watch?v=LkH2r-sNjQs
[2] That said, I don't see how secure electronic voting can possibly be cheaper than paper voting. For voting machines to be secure, you have to manufacture them in a very audited manner, with little to no foreign sourcing of parts, you can't leave the machines unattended for long periods of time (aka, reusing them between elections is probably a no-go) and you have to build them in manner that is secure against voters tampering with them in their private booth.
This won't change until executives go to jail.
A few years ago, we were fighting against tight deadline and skipping unit tests, QA, processes, etc. Someone brought up one of the recent major breach (Equifax?). Developers started to say that people will go to jail. Basically, devs were using this breach to imply that they will personal responsibility for releasing a product that might have security flaws. Our director laughed and said no one will go to jail and if our product ever got in trouble, they will personally take responsibility.
This is extremely domain dependent, and should be handled as such. And in some cases it already is - look at the testing / verification space shuttle code goes through vs your friends cat video side project website.
I disagree. The needed quality of your software changes dramatically depending on what it is used for. Something that helps someome semi-automate their workflow where bugs just mean they have to do things manually (as things that are wrong fail quickly and obviously) is something where what matters is speed of release and features. Something calculating how long people should be in prison needs to care about quality.
Anyway, the courts are the ones that have the biggest share of the blame here. Believing an unreliable witness for the prosecution is a common cause of injustice.
If the problem is the software, then use less software. Perhaps we shouldn't simply take it as a given that moving processes into software isn't always the right move?
And according to the article, the full number may actually be something like 900 people.
>Campaigners believe that as many as 900 operators, often known as subpostmasters, may have been prosecuted and convicted between 2000 and 2014.
How do you make this mistake almost 1000 times over 14 years before someone suspects the system data may not be quite right? Also, even if you do completely believe the data, how can you convict them all without additional supporting evidence, like new purchases that don't seem to fit their salary, suspicious bank transactions or balances, records of unusual system access or them actually manipulating data, etc.
It pains a very bad picture of the Post Office, including:
- an expert witness from Fujitsu, who developed the system, "had been aware of at least two bugs which had affected Horizon Online[...], but had failed to say anything about them or about any Horizon issues in his statements";
- POL arranged a number of conference calls to discuss problems with the system; "instruction was then given that those emails and minutes should be, and have been, destroyed";
- "there was a culture, amongst at least some in positions of responsibility within POL, of seeking to avoid legal obligations when fulfilment of those obligations would be inconvenient and/or costly"
Further, once a number of convictions had been secured, the Post Office then used those convictions in later trials as evidence that the Horizon system was robust and reliable.
All in all, a prima facie criminal conspiracy by the Post Office.
It's very much a case of assumed infallibility of "scientific evidence," which in this case were computer records.
It's also very much a case of UK judges greatly, greatly disregarding the process, which fully reneges on their oath.
Country's legal system can't function if you have judges who can lightheadedly throw out the process out of the window 1000 times over 14 year.
I wonder if any of the prosecuted were in Scotland?
In Scots Law there's a fundamental rule of Corroboration: https://en.wikipedia.org/wiki/Corroboration_in_Scots_law
There must be two source of independent evidence for someone to be convicted of a crime. I'll be interested to see (if there's genuinely no corroborating evidence beyond the computer records) how many prosecutions went ahead north of the border.
The requirement for corroboration in such a situation would probably be met by having someone "speak to" the digital evidence and audit trail.
For example, if you have CCTV evidence, the CCTV is one piece of evidence, and it would be corroborated by a witness statement of the victim identifying them from the CCTV.
Corroboration is an important and useful safeguard, but I don't think it would necessarily have outright prevented this. Perhaps it would - maybe it would have raised the bar on scrutiny of the evidence, by there being a general higher expectation?
I'd expect there was prosecutions north of the border seeing as the post office is UK-wide so be good to see how they went.
I mean, I don't think anyone assumed they suddenly and inexplicably became thieves, just that the fancy new software finally caught people who have been scamming the post office for years. Obviously the software was completely wrong and it's criminal what happened to those people.
I think the core point here is how imbalanced this process was: postal system builds a new accounting program that shows money is missing. these people were convicted solely on the evidence that software said so, there was no burden on them to show that the money was actually missing. I mean, hard for me to grasp how is that possible. anyone can write a program that shows something. how is this sufficient proof to send people to prison? does it not need to touch some objective reality at some point?
My suspicion is that the Post Office wanted to do this "at scale" and "automate", and just assumed blindly their own records were accurate, because well... They must be!
Had they actually tried to investigate these as one by one offences, you'd gather evidence of individuals concerned making huge cash transactions to buy expensive cars and holidays. And when you didn't find any evidence of this unexplained enrichment (as there wasn't any), your investigator would point this out, and you'd realise you didn't have a case.
Similarly a photograph of the subpostmaster getting into their outright-owned Lamborghini would have been useful evidence there. The absence of any of the evidence of this enrichment seems absent throughout. Let alone the detailed forensic accounting to determine what was actually taken. I suspect the issue was they simply didn't have any way to tell what should have been there, other than what the defective horizon system said... They were trying to run at national scale, without enough ground truth information to validate their assumptions and detect the issue.
My second thought was that most accounting departments I've worked with actually wouldn't do that, would blame fraud, and then would congratulate themselves at how much better they've gotten at detecting it!
It took weeks to fix the problem.
On the other hand, I think Shanghai didn't check well enough--there was one simple test they could have done but didn't: Hand held geiger counter, see what's hot. Body equally hot, baggage not hot, it's medical.
Why couldn't the US cops do the same thing?
Patient claims medical--call the facility and ask if they should be hot.
However, having read about their stupidity I would be inclined to get a card from the facility even if I didn't expect to be going anywhere with radiation scanners. (My wife had a card--which was sitting at home in the pocket of the jacket she had planned to wear. She changed her mind on flight day and didn't think about the card until she tripped the scanner. Note that she probably had an easier time of it than a typical tourist would have as she speaks Mandarin at native level.)
>For the first 10 years of Horizon’s existence, transaction and account data was stored on terminals in each branch before being uploaded to a central database via ISDN. Our source says this part of the system simply did not work.
>“The cash account was a piece of software that sat on the counter NT box, asleep all day,” he said. “At the end of the day, or a particular point in the day, it came to life, and it ran through the message store from the point it last finished. It started at a watermark from yesterday and combed through every transaction in the message store, up until the next watermark.
>“A lot of the messages in there were nonsense, because there was no data dictionary, there was no API that enforced message integrity. The contents of the message were freehand, you could write whatever you wanted in the code, and everybody did it differently. And then, when you came back three weeks later, you could write it differently again.”
And down further
>Speaking to Computer Weekly in 2015, the anonymous source told us: “The asynchronous system did not communicate in real time, but does so using a series of messages that are stored and forwarded, when the network connection is available. This means that messages to and from the centre may trip over each other. It is perfectly possible that, if not treated properly, messages from the centre may overwrite data held locally.”
>Four years later, former Fujitsu engineer Richard Roll wrote in a witness statement to the High Court: “The issues with coding in the Horizon system were extensive. Furthermore, the coding issues impacted on transaction data and caused financial discrepancies on the Horizon system at branch level.”
BUT the most important part
>So far, nobody at the Post Office or Fujitsu has been held accountable
Meanwhile in the Netherlands, ~26000 people have been branded as fraudsters by the tax office due to a way too strict child benefits law. More than 100 probably entirely innocent people fled the country. Even the compensation that is now promised is only slowly trickling towards them, and likely to be snatched up by debt collectors - including even the tax office itself, which is still partly unrepentant. Okay, they haven't been sent to jail directly, but the scale of this is huge.
And this is the most important part.
"In December 2019, at the end of a long-running series of civil cases, the Post Office agreed to settle with 555 claimants."
So settlements in 555 of the original 700+ prosecutions.
"It accepted it had previously "got things wrong in [its] dealings with a number of postmasters", and agreed to pay £58m in damages. The claimants received a share of £12m, after legal fees were paid."
But 80% of the settlement money went to lawyers. Ugh.
I disagree. Even the ambulance chasers here in the U.S. take around 40% as their contingency fee. 80% is just...wow.
Edit: "ambulance chasers" in this context means very opportunistic lawyers that are primarily motivated by money, and not helping their clients. I don't see how that term is disparaging any victims/clients. The comparison is that even outright greedy lawyers aren't taking half+ of the settlement. In this case, using £250/hr, the lawyers spent 88 lawyer years worth of time (184k hours).
The cost of the legal work is uncorrelated to the size of the damages.
Limiting legal fees just makes it not cost effective to pursue justice for smaller damages with more complex cases.
It's absurd bordering on evil to say the problem here is that people got paid too much for their excellent work (fighting against the resources of a corrupt major corporation and a corrupt major world government!) not that the perpetrators was under punished for their horrific crime.
The heroes who saved 700 people's lives deserve the money more than super-wealthy psychopathic perpetrators.
Because for the lawyers to get all the money each time harm happens means they more from harm to people than the people themselves benefit, this is a perverse incentive to keep the system exactly as it is for people who often become our lawmakers.
This also applies to 80/20 splits.
No, you've misunderstood entirely.
I wonder how other countries get by without "ambulance chasers". The only country I know that has them is the US, and their existence is the sign that something is fundamentally wrong.
There's obviously a lot of detail there, but it does still feel to me like more than £12M should have gone to the actual post workers. That's ~22k each.
Where evidence from IT systems is being used as a large part of a prosecution, it seems that it should have some kind of scrutiny as to how those systems operate.
One option would be allowing the defence to see details of how the system works, testing that was done and known bugs, but that would require a lot of expensive work by legal defence teams, especially where the system is complex.
Another option would be some kind of certification of IT system operation, but again it would be hard/expensive to do and very incompatible with rapid development techniques.
The real issue here was that Post Office refused to recognise that, although computers themselves are mostly infallible, computer programs are never infallible. They conducted their activities and took actions based on assuming the reporting was flawless.
Then the really serious problem is that in cases where the fallibility became more visible, they consistently and systematically covered it up and pressed forward with their incredibly aggressive enforcement work anyway, knowing how much damage it was doing.
This is unquestionably an issue of abuse of power and position.
What do you mean? Hardware is fallible too, just less often than software. This may cause problem on its own e. g. bit flips in non-ECC memory, HDD which lie (reply to flush cache before data is actually written) or HW can trigger software errors, e. g. HW can crash at random moment and SW can be not designed to handle this properly.
I look forward to finding out if this was a “fraud system gone wrong” or a more basic ledger system failing to do sums correctly.
Partially addressing your question though, if you were to insert the words “AI” and “bias” into the sentence we as an industry are starting to figure this out. The certification and testing processes you mentioned are there in cases where a team’s mature enough to have both a data and model lifecycle worked out. You see words like MLOps trying to describe how to do that effectively in production.
For example, my work has both a design approach (in both the product design touchy/feely sense and software architecture sense) that includes questions and practices that will help to reason through data needed to address a problem, what can go wrong with that, and how things look when it goes wrong. The last bit is the most interesting one to me. In terms of practical engineering, inference results generally should have some sense of lineage - of data, model, and training services which explain how you got to a given answer, including what inputs were considered or ignored.
An interesting side topic with this is that poor implementations can result in inexcusable differences that affect downstream systems. For example, if a particular model has predicted something like “this transaction is suspected to be fraud” it better be consistent from run to run, and the input data better be consistent over time. If either of those changed - explaining that to the consumers of the data is essential to them understanding that either the model changed, the data changed, or both.
Corroborating evidence. In this case, where was the evidence that this money was ever in their possession? Was it ever sitting in their bank account? Was it buried in the back yard? Did they buy fancy sports cars or houses? The prospect of thousands of people stealing money without a trace of the cash is fantastical.
In general, I'd say electronic evidence should need to be corroborated with physical or other types of evidence to achieve a conviction. It's too easy for electronic records to be falsified, either through software bugs or outright malicious intent.
Were all these people accused of theft with not a single record of the yachts they bought with all the money they supposedly stole?
I would assume most of these people would be able to turn over a complete financial record of their lives (ie. I was paid £x, I paid taxes of £y, and here is a bank statement showing how I spent it, and here is whats leftover). How exactly can you imprison someone for theft of money if they can present that?
And all the evodence the prosecution has are electronic records, entirely in their control, which they could fake and which were never checked by a third party for basic errors? This is a colossal miscarriage of justice
There have been genuine cases where accountants, bank managers, and so on have embezzled large sums of money, including in cash, and spent it all untraceably on things like feeding a gambling addiction.
That's financial crimes 101
When people were unable to continue making up that shortfall this was seen as further evidence of their criminality: "they've spent the money", "they've hidden the money", and not "they never had the money".
That's some £20'000 each. A pittance for years of suffering and inability to work.
The judgment is blistering.
What can be done? Mandatory audits, pen testing?
If this is an organizational problem, more vacation? limiting overtime? rethinking employee incentives?
In the UK in the wake of the 2008 banking crisis, a number of positions in banks became criminally liable for issues under them. If you're director-level or above (I think?) then you may be ultimately put in prison for negligence or issues like that which occur in your department. This is rare, not sure if it's been used yet, but it effected a cultural change in consumer banking as a bunch of execs suddenly had their necks on the line if someone under them did something wrong. I don't believe this is too hard-line in practice, I think a defence is "look at all these reasonable steps we take, we couldn't have foreseen this", but it had the impact (source, a good friend of mine is bordering on this level in a UK bank).
I wonder if a similar thing could work in a wider way across more industries - not with the intention of criminally punishing lots of people, but with the aim to change the culture around responsibility to the public and other stakeholders in the work that we do.
Not taking software results as a fact. Software report stating X in court should be equivalent to "the person who wrote this in a hurry would say X, but it's not a sworn testimony".
We should have the person presenting any report like that be personally responsible for the contents. If they aren't willing, it shouldn't be presented.
I don't think making it personal works at scale. You can't reasonably expect everyone giving evidence in court, say every individual police officer who is a witness to a speeding offence, to be a technical expert on the technological tools they are given to do their job.
Instead, as you implied in the previous paragraph, the weight given to any evidence derived from technology should be proportionate to the credibility of that technology. If it's a device that has to be vetted and approved according to strict regulatory standards and in court there are two other concurring sources of evidence, that's clearly a much stronger case than a single reading from a single device whose calibration has reasonably been called into question at trial that is being presented as the only evidence in that trial.
That's what I was going for. If the officer doesn't understand the limitations of their tool, they shouldn't testify in court beyond "I pointed it that way and read the number, as trained".
There are existing cases where the speed reading is contested because the handheld speed cameras can move slightly and bounce first off the side mirror then off the reg plate giving you "extra speed".
My point was that if you say "that person was speeding" you should be responsible for that statement afterwards, but you can say "I used the provided tool and got reading X", at least the doubt is there.
Corporate structure helps diffuse and deflect responsibility. Each group (executive leadership, middle management, and ICs) gets to diffuse and deflect responsibility and liability onto each other.
We already have all the positive incentives in the world - cash money. It's not enough.
Risky click.
Post office employee can’t afford a lawyer that would do any extra work
Earn enough so you can afford your rights... and appeals court where that actually matters :)
https://www.bbc.co.uk/sounds/series/m000jf7j
It's really well paced and includes contributions from many of the sub-postmasters affected by this scandal.
https://www.theverge.com/2021/4/23/22399721/uk-post-office-s...
As a software person, I would like to read a more detailed post-mortem on the issue from a code, engineering and project management point of view: e.g. who built this software, when, with what process, with what safeguards, and how did they fail? Was it in-house or outsourced, and if so, to who? Did it run on-premises? What checksums, what backups? What lessons, if any, did they learn and what can we learn?
https://www.bbc.co.uk/news/business-56859357 (also from today)
https://www.computerweekly.com/news/252496560/Fujitsu-bosses...
https://www.private-eye.co.uk/pictures/special_reports/justi... [pdf]
https://www.bbc.co.uk/sounds/series/m000jf7j [podcast series]
Edit: posted later but might as well add it here:
Convicted Post Office workers have names cleared - https://news.ycombinator.com/item?id=26924882 - April 2021 (152 comments and counting)
Some past related threads - pretty sure there have been others:
UK Post Office: Error-laden software ruined staff lives - https://news.ycombinator.com/item?id=26905528 - April 2021 (3 comments)
UK legal system assumes that computers don't have bugs - https://news.ycombinator.com/item?id=25518936 - Dec 2020 (24 comments)
Post Office scandal: Postmasters celebrate victory against convictions - https://news.ycombinator.com/item?id=24661321 - Oct 2020 (2 comments)
Faults in Post Office accounting system led to workers being convicted of theft - https://news.ycombinator.com/item?id=21795219 - Dec 2019 (103 comments)
Post Office hires accountants to review sub-postmasters' computer claims - https://news.ycombinator.com/item?id=4143107 - June 2012 (1 comment)
I wonder if the post masters can now go after the Post Office for damages?
Another small point of interest that doesn't seem to be making the mainstream reporting yet is that under our legal system the state prosecutor (the Crown Prosecution Service) has the power to take over and, if appropriate, shut down any private prosecution. When the inevitable inquiries publish their conclusions, the fact that so many bad prosecutions were successfully brought over such a long period might reflect poorly not only on the Post Office and on the courts and lawyers involved in the convictions but also on the CPS for not intervening. This could become politically significant, because the current Leader of the Opposition was in charge of the CPS around 2009-2013, the last five years when most such prosecutions were being brought. That could leave him in an awkward position if he's attacked over his record during the next general election campaign, given that his party is exactly the one that's supposed to stand up for working class "little guys" like the victims in these cases.
Edit: I get it.
I think he/she meant customer, I found the idea of someone who makes fancy dress giving technical feedback amusing.
<!-- $Revision: #6 $ $Change: 54072 $ $DateTime: 2004/02/16 15:56:30 $" -->And yes, the negative side is that every time something goes wrong, BT really can't fix it any faster, it's all down to OpenReach to maintain the network. But on the other hand, it always goes through OpenReach, whether you are with TalkTalk, BT or Sky, so the entity responsible for maintaing the network isn't the entity selling you broadband for home.
Thus, the two companies extracted an exorbitant rent for the formerly public goods they controlled. The fact that some of this rent went to inefficiencies of running two separate companies on an illusionary arm's length basis does not really improve matters.
https://www.openreach.com/about-us/our-leadership-and-govern...
https://www.bt.com/about/bt/our-company/group-governance/boa...
Openreach
Mike McTighe Chairman
Clive Selley CEO
Matt Davies Chief Finance Officer
Edward Astle Non-executive Board member
Liz Benison Non-executive Board member
Andrew Barron Non-executive Board member
Jon Furmston Secretary to the board
Simon Lowth BT Group nominee
BT
Jan du Plessis Chairman
Philip Jansen Chief Executive
Simon Lowth Group Chief Financial Officer
Adel Al-Saleh Non-independent, non-executive director
Sir Ian Cheshire Independent non-executive director
Iain Conn Senior independent director and independent non-executive director
Isabel Hudson Independent non-executive director
Mike Inglis Independent non-executive director
Matthew Key Independent non-executive director
Allison Kirkby Independent non-executive director
Leena Nair Independent non-executive director
Sara Weller Independent non-executive director
Rachel Canham Company Secretary & General Counsel, GovernanceThough as a nitpick of your nitpick, they weren't truly independent until the relevant provisions of the Postal Services Act 2011 came into effect on 1 April 2012. What we know today as the "Post Office" and "Royal Mail" had a long history before that.
There's no way this is true.
> There were more than 700 prosecutions based on Horizon evidence. The commission and the Post Office are asking anyone else who believes their conviction to be unsafe to come forward.
On second thought, I guess it may be, since even after the abuse was proven they are still holding innocent people on false charges.
Well, same government first destroyed immigration papers and then deported and otherwise ruined the lives of their own citizens ( Windrush scandal ). I'd love to see the perpetrators in jail but fat chance.
Will any developers involved in this horrible scandal ever will be held accountable for their work?
I wonder if the developers who were responsible for such a bug-infested piece of software realise their work has destroyed people's lives? (They presumably never met the users of their software or were so distant from end-users that they never considered the consequences of their actions.)
Do those developers even realise it was their incompetence that caused untold misery? Or are they completely detached from the events in this scandal and see themselves as simply cogs in the 'system' and thus blameless?
Blame must be apportioned to management. But also I feel it's too easy as a developer to see yourself as part of a team and thus absolved of any individual blame. You're subsumed in the "team" - and ultimately no-one takes responsibly.
Even with management at fault, one cannot deny that it was the developers who produced absolute garbage.
I hope the developers who worked on this system, no matter how much they feel they are not responsible for the failure of this project, will reflect on how the impact of software they built had devastating consequences on people's lives.
As far as I can gather this malignancy escapes permanent legal destruction primarily by shedding all of its staff every 20 minutes
Today's update isn't there yet but should be shortly.
When: I use this software
Then: I should not be falsely imprisoned for 3 years.
Yeah, me neither.
175 and 53 comments also posted 3 hours ago: https://news.ycombinator.com/item?id=26913183
When ATMs were introduced in Canada in the 70s/80s, it was common to believe they were infallible. When customers claimed they were short-changed by machines, often they were prosecuted for fraud or attempted theft.
I'm sure HNers can think of dozens of ways a machine could be wrong ...
https://en.wikipedia.org/wiki/Automated_teller_machine
Also, regarding the Postmaster article, note that somebody working on that project would likely face great difficulty in convincing anybody there was a systems problem.