Proposed amendment to legal presumption about the reliability of computers
postofficescandal.uk
postofficescandal.uk
Anyway, it was later proven the computer system was incorrect but the government there dragged their heels on exoneration and compensation.
To clarify, there was not _one_ bug, but hundreds.
https://en.wikipedia.org/wiki/British_Post_Office_scandal#Pr...
From my read of the information publicly available, there was a fundamental lack of distributed/transactional system understanding from the developers at Fujitsu.
This[1] article recently posted here[2] reminded me of the Post Office Scandal.
The lack of respect for established CS theory (transactions and distributed systems) and established accounting practices (double entry book keeping or even the idea of a ledger) is mind boggling.
[1] https://news.alvaroduran.com/p/engineers-do-not-get-to-make-...
The number one rule for engineering domain applications is to understand the domain.
I would blame the perennial neophilia and lack of (or inadequate adoption of/respect for) standardized texts in the industry. Though, to be fair, a lot of this does come down to the rapid changes in the technology.
Iterative development is necessary for software, of course, but this should be understood as a necessity due to the medium, not as an excuse for skipping research and design. A lot of these domains (especially something as critical as accounting) should be solved problems.
Where signing off contracts does have some implications beyond "it works on my computer".
In al seriousness, Engineering is about verifying systems to make sure their lifespans and failure modes are known, up front.
This has a legal dimension and a practical one. Legally you can make people liable for unreliable systems. But you can also be liable for failure to maintain properly, or failure to warn about impending calamity. Because it's all documented and verified.
Practical you can live worry free in earthquake and flooding proof buildings, trusting in the diligence of Engineers, and maintenance workers, because they and others have liability imposed on them.
For software this is only the case in a few sectors. For buildings in all cases. Not comparable.
Any life can be absurdly destroyed via malware, security exploits, accounting gone wrong, a database deleted in production,....
People also don't put up with faulty products, why should computing be an exception, shitty ship now fix later culture?
And above all, calling oneself "engineer" out of a bootcamp, has nothing to do with Engineering.
No doubt management also oversaw the development of the system and rushed it to production.
A healthy culture should accept failure as inevitable and learn from it when it occurs. It should also listen to the people who know best: the engineers who built the thing. You know, like the aerospace industry.
The damage that morons in suits do in pursuit of their bonus cannot be overstated.
Normally I'd give the developers the benefit of the doubt. But the sheer number of issues, and how fundamental some of them ~were~ are[1] leave me little room for sympathy.
https://en.wikipedia.org/wiki/British_Post_Office_scandal#Pr...
Transaction idempotency is such a basic property for a financial system that I struggle to believe that Horizon was tested in any meaningful way.
"the engineers who built the thing" (Gareth Jenkins) are also under investigation for perjury.
[1] Horizon is still in use, in its buggy state, with replacement scheduled for 2030....
The developers were just doing their job. It's management's responsibility to construct a functioning system of checks and balances and understand the limitations of their systems, both of which they failed to do. If it weren't for their hubris the fundamental issues with Horizon could have come to light much earlier.
Let's also not forget that the reason executives are compensated well is for them to take accountability in situations like this.
More broadly, your idea that this is solely a management problem is how we end in situations where developers are being told to unquestioningly code some design exactly as given, which never works. You don’t get professional judgement if you don’t accept responsibility, too.
But I would also say that that kind of toxic management is absolutely a part of "software engineering culture". How many horror stories do people on here have of managers who care nothing about the quality of the product, only meeting the deadline so they can get their bonus?
"Software engineering culture" is way, way more than just "how write good code." It includes how we work, how we manage/are managed, how we advocate for ourselves, or fail to do so, and much more.
It certainly includes the very common resistance to unions among programmers, and assuming this was caused by management pushing a known-bad product out the door, a strong union would have (at least potentially) been able to stand up to such demands.
The thing literally went into a criminal court as evidence, and was "presumed correct" in a way that overloaded any technical or reasonable discordance.
The largest failure here was from the judges and lawyers. The software failure isn't even relevant.
Try suggesting to use a tool like TLA+ to validate some complex design and the most likely scenario is that people will laugh at you, even if it's a critical component for the business.
Most decisions in the industry are based on weak anecdotes and unfounded opinions of underserved "authorities".
And even if you do the right thing, if a competitor comes in and offers to do the "job" quicker and cheaper because they're doing the wrong thing. You may have the moral highground but that doesn't pay your employees' salaries.
What we need is a better framework for punishing bad software, in an ideal world without a bunch of red tape and reducing the burden on non experts identifying what is or isn't bad behaviour.
So like engineering licensing and insurance?
It doesn't strike me as unreasonable, software engineers are now able to cause billions in damages and/or cause loss of life via primary or secondary effects.
Sure, one of software's greatest strengths was that anyone could learn it and it'll be sad to lose that but that's not really a reason for structurally enabling things like the Post Office scandal.
You probably don't need accreditation to serve cat pics but things dealing with money and life/death should. But IANAL so hopefully someone else can bring better insight to this area.
People will still be able to learn how to program and actually program. But if they take money or deal with people's private information, then they'll need to comply with the standards that will be regulated.
I think we need to start thinking of an individual's persona which includes all the information about them that is online or in government (non secret) files.
That needs to be considered when designing regarding regulations for software that interacts with someone's persona.
So anyone can set up the equivalent of an art stand in the park (serving cat pics), but if they start either selling cat pics or selling advertising that relies on collecting information about the personas on the site, then that needs to be regulated.
You can even have non-licensed people doing work, and a licensed individual signing off on the end result. They would need to review the designs and work to make sure they agree with how the work was done, because it's their license on the line if something goes wrong because of bad craftsmanship.
The law may require to use the ones that are certified if you are doing something sensitive. It doesn't need to be universal necessarily, but it should apply to public tenders for critical infrastructure at least.
Software isn't made of physical materials anyway, it's speech. How about instead we impose open source requirements to enable public verification of critical systems?
Some software is critical infrastructure and needs to be treated as such. We are not special. Every other engineering discipline has gone through this same process as and arrived at the inevitable conclusion that government regulation is essential, but only after causing unthinkable damage to the public first
I say we regulate the word engineer the same way it is in many countries for real engineering. if you don't want to progress beyond code monkey, you can be a software developer and innovate yet another react clone. if you want to be called an engineer, you learn and follow the regulations.
And it is not as absolute as you make it sound. Only dependencies for specific critical functions may be regulated. And they don’t have to literally force a whitelist of dependencies on you, just whichever has been certified as appropriate for that purpose.
[1]: https://en.wikipedia.org/wiki/FIPS_140
[2]: https://csrc.nist.gov/Projects/fips-140-3-transition-effort
Sure, now that the infrastructure for this has been built, it can be configured to require stronger crypto then FIPS does, but that infrastructure would never have been built without the likes of FIPS, and the government mandating it's use. And I know this because even with all of the hard engineering work done of building that infrastructure, there are no commonly used stronger policies; because the only people who actually care are the ones forced to care by the likes of FIPS.
Our electrical standards might not the safest way of wiring buildings, and not what we would come up with if we wrote the standards today. But they are orders of magnitude safer then what electricians would be doing without the standards.
What prevents regulatory capture?
Perhaps without the certifications lots more people would have died. I'm just an armchair analyst. Just food for thought.
Is Fujitsu run by engineers?
Food, drugs, healthcare, consumer products, chemicals, cars, planes, trains, buildings, utilities, energy, infrastructure, salaries, loans, investments, accounting... Even media requires some licenses, receives age ratings, and has restrictions on advertising.
It's not rocket science, this is normal for every single other industry.
Rocket science is one of the few industries that's actually seeing active innovation.
What they need to specify is the standards for software that certain types of organizations can use. Like government agencies, government contractors, medical organizations, construction and engineering firms, and probably some other kinds of large private businesses, depending on their industry.
Basically, if the software your organization uses can cause the level of destruction that Horizon did, it needs to have specific certifications, or you can't use it.
In order for such software to be certified, it needs to meet certain clearly-defined standards of quality, potentially including having all the technical leads of some level (or just all the developers, depending on various factors) be licensed, and have their licenses on the line of something like this scandal occurs.
It's not a panacea, and it would definitely be an absolute bear to get the terms of all of it defined both clearly and in a way that is likely to actually produce a quality product, but IMO it is likely to be worth it in the long haul.
all it takes is enough people to die, and/or for rich people to lose enough money and it'll become the rule.
Just mandate open source if using public money.
If someone prefers solution B to solution A, bringing up a situation that had neither is not a counterargument.
Software needs to be transparent, a human expert worker needs to be able to verify the result a software generates within reasonable time.
There is no expertise for software that you could delegate to aside from an entity using some form of integration test.
This is becoming more and more important as the AI industry is pushing non-deterministic computing further and further. There will be court cases where the full automated decision chain will be called into question, and a default assumption of "well, we don't have any logs so we should assume the software did the right thing" terrifies me.
Even speaking from an IC/non-managerial place, far too many technical problems in businesses are really just symptom-alleviation (or worse, performative look-I'm-doing-something theater) for a deeper problem which involves misaligned incentives for humans.
> So like engineering licensing and insurance?
How is engineering licensing and insurance punishing bad software ?
Microsoft is still going strong and all they do is "checklist security".
It's more likely that managers are just incompetent. Not being able to distinguish between infrastructure and "decoration" means all their decisions are at best superficially motivated.
The punishment we have for this is unemployability and bankruptcy. It will happen by itself if you let it.
A framework for "punishing bad software" sounds to me to be hiding the ambition to "protect bad managers from consequences of their decisions".
In my career, I have never seen a manager see consequences for making the decision that values "money now" vs "avoiding things going wrong later". I do not believe that it will happen by itself.
Imposing some formal framework is more likely to insulate managers even further while making software developers accept legal responsibility beyond their pay.
yeah, nah.
"No one ever got fired for buying IBM"
after decades of incompetence the multinational contracting firms are still going fine. IBM still runs fine and they're focus is now even more in the insulting side of the business.
"Majority of Subpostmasters still getting unexplained Horizon discrepancies" - https://www.postofficescandal.uk/post/majority-of-subpostmas...
One of the things the Post Office did was sell travel money, but the whole system was never really designed for ForEx operations, so it didn't keep track of exchange rates over time. The result is that reconciliation used the exchange rate at time of reconciliation instead of at the time of trade. So, if the foreign currency had gone up in value, it would show up as GBP missing.
Wow, that's... dumb.
Given the Post Office had a reputation for really good exchange rates, this one design flaw might be responsible for a significant portion of the problem.
As low as it takes for a profit!
I think it would leave me furious for weeks and push me into a depression rut.
I'm trying to take the whole debacle as long term inspiration to be excellent at what I do - it's tough to stay positive when so many people involved (Fujitsu, PO upper management, the original prosecution) seem entirely morally bereft, with little chance of consequence.
When you have such a widespread and ongoing problem it becomes clear that such a large proportion of postmasters can't be criminals. Computer bugs are well known. Eventually it is going to come out that the computer is wrong. Why double-down? The earlier you admit a mistake and apologize the lower the impact and the less anyone cares. They had a built-in scapegoat that everyone understands and accepts: the vendor's software had bugs! We have daily meetings to yell at them to fix the bugs we promise and we will fix the problems ASAP.
Or do the sneaky thing and fix the issues, stop prosecuting postmasters, and ignore the ones you prosecuted by mistake. Cynical, cruel, and immoral... but contains the damage.
Instead the UK Postoffice seems to have just let the problems continue while simultaneously allowing prosecutions to go ahead knowing they were faulty. Literally the worst of all worlds: ongoing accumulation of liability, now with provable malice!
I heard some convictions of innocent people have been overturned, or are in the process of. But new convictions of the actually guilty... no news about any such thing. Maybe I'm just uninformed.
Fair enough. The investigation is still ongoing but as of now I don't think anyone who knew (or should have known) has been punished. The UK public are the ones on the hook for recompense.
The real scandal here is that there were hundreds, and those at the top knew this, but instead doubled down.
I am pretty sure more dependable systems send the odd person to jail - there have been many cases where someone was lucky not to be convicted.
https://www.computerweekly.com/news/366587174/Fujitsu-set-fo...
Both the gov and Fujitsu and the post office absolutely knew it was a bug and intentionally hid the fact while the post masters lives were ruined.
However bad the bug was, the cover up was _much_ worse.
The main one is that the post office management/officials at some point became aware of the bugs and that they were ruining lives of innocent people and they knowingly kept lying to save their asses.
The inquiry page has all of this and more: https://www.postofficehorizoninquiry.org.uk/about-inquiry
I’ve read through it, it’s long but it’s a good (while terrifying) read.
And wiki has rest it the judgments: https://en.m.wikipedia.org/wiki/Bates_%26_Others_v_Post_Offi...
I have a lot of respect for the judge after reading this. Here’s a quote describing Post Office evidence:
“bare assertions and denials that ignore what has actually occurred… [amounting] to the 21st century equivalent of maintaining that the earth is flat”.There's a little more to it. Most of the comments here are focusing on "correctness". And yes, the amendments to section 69 do something towards tempering its ridiculous and dangerous "presumptions".
But the (UK Post-Office) story is that the Horizon system had back-doors in it. Fujitsu denied this. "Corrections" were made to systems without operator knowledge - to fix actual errors caused by a terrible database sync script full of race-hazards, faulty locks and duplicated state.
The cover-up began life as engineers trying to hide up technical mistakes. It escalated to senior executives trying to cover up financial and political mistakes. It ended with the Crown colluding in covering up judicial mistakes. It is an exemplar of hubris, pride and egotsim resting on a refusal to give up a religious belief in technology. Were it not for the courage of a few (including judges and MPs) they would have gotten away with it (if it weren't for those meddling kids)
The case stands as an important landmark that you cannot "hide behind" technology as a means for abuse and injustice.
The amendments are welcome but insufficient. They open up a good opportunity for cybersecurity people to work with lawyers now.
There are two outstanding problems:
Proprietary code. If you cannot examine the system then the right to challenge it is meaningless. This requires changes to investigatory powers/discovery if anyone wants to use "technical correctness" as a base for argument.
Malicious function. While the discussion revolves around correctness it is incomplete. Many systems (perhaps not the Horizon system) are not faulty, they work perfectly well to deceive, manipulate and swindle.
I'd still push for a complete reversal of presumption [0]. Where software is part of a legal dispute it should "take the stand" as its own witness, in that formal proofs of correctness (a very VERY high bar in software engineering) need to be brought in front of the court. Otherwise the reasonable presumption is that an error or hidden malicious coding "cannot be ruled out".
[0] https://cybershow.uk/episodes.php?id=23 https://cybershow.uk/episodes.php?id=24
Yes there is operational separation but it's not like they're wholly unrelated and the government totally guilt free
Whether the story was true or not, the government is just bad at science. It's how we get stuff like bite mark patterns and facial recognition warrants.
Every person who has ever programmed a computer or worked in any complex system knows they can't be relied upon 100%.
Not least because it seems to go against the core concept of "innocent until proven guilty" that the whole legal system is meant to rest upon.
If we're in a court and there hasn't been a decision yet, we're there because we're dealing with some kind of complicated edge case where one person has a strong argument for one thing and another for another.
If one then decides to bring some problem up-- whether with how evidence is being judged or anything else, there can be no justification for ignoring him. This is why I like free evidence evaluation in Swedish courts and the absence of rigid precedent. Every question must then actually be dealt with. We do have this kind of idiotic rulemaking in other parts of our legal system though, so we're not fully free from it.
Is this actually a fact, or a fact taken to it’s logical conclusion to presume a new “fact”?
The article cites “mechanical systems” as being infallible, and reading that language, it reads to me as some archaic legislation that never got updated for computer software. Instead, precedents got set over time by enterprising lawyers, but setting a precedent when it’s convenient is not the same thing as writing a law.
When I see mechanical systems, I think of something like an abacus. I’ve never used one, but I suspect the abacus itself is infallible. It’s open, it’s transparent, it is easily auditable, and the same inputs will always produce the same outputs. There is no black box translation occurring, like occurs with computer software.
In the UK, they're pretty much the same thing. You need a new case or a statute law to overturn a precedent.
Apparently the law was introduced along with speed cameras, as they were continually being challenged in court.
It's worse than that.
The law was fixed in 1984[0] and then the fix was intentionally reversed in 1999.[1]
[0] https://www.legislation.gov.uk/ukpga/1984/60/section/69/1991...
The change in 1984 wasn't a 'fix', it threw the baby out with the bathwater.
1. Historically, mechanical tools are presumed to be working well. This makes things simpler. The example quoted by the Guardian is a good one[0]: if someone wants to question the accuracy of a clock, it's on the person claiming the inaccuracy to prove their point.
2. In 1984, it became clear that computers are not just simple mechanical tools, and they were explicitly excluded from this assumption, by saying that computer evidence should be considered 'hearsay' (and therefore inadmissible) unless the prosecution can prove that the evidence is correct, either by a certificate from someone who can reasonably be expected to certify the correct functioning of that particular evidence, or by oral evidence.
3. This meant that anyone depending on the reliability of evidence from a computer (or piece of software, hardware, etc.) as part of their legal argument could be called upon to prove this, and the burden of proof lay with them (i.e.: as a defendant, I could require the prosecution to prove that the computer works as it is intended).
4. Following a review, it seems to be basically the conclusion that the requirements are inconsistent, unnecessarily onerous and time-consuming, and the way it was written was allowing criminals to get off on technicalities because the prosecution were not able to prove minor or irrelevant points about the functioning of the computer, and anyway other countries don't have any special rules about computers. You can read for yourself the recommendation here: https://cloud-platform-e218f50a4812967ba1215eaecede923f.s3.a... (starting page 200 of the document, 215 of the PDF).
5. In 1999, the specific requirement for computer evidence to be treated as hearsay was removed.
The law does not say that computers are infallible. It is still possible to challenge the accuracy of a computer system, but the burden of proof lies with the defence. It's not going to be good enough to say 'well I don't know what happened, it must be a computer glitch', and as a result, cause the prosecution to need to produce evidence that the terminal in the Post Office was working correctly, as well as all of the back end servers that may have been responsible in some part for producing the output.
There's an extent to which I think this is reasonable. If I'm accused of fraud based on evidence recovered from a bank computer, it should not be the case that I can require the prosecution to prove that the bank's computers function correctly from first principles, and the evidence be thrown out in case the prosecution are unable to do so.
The problem with the Horizon convictions is that in many cases, the evidence produced by computers was the only evidence. Also, as the Post Office has its own prosecutors, they could chase and prosecute cases which would not normally have been tried by the CPS due to lack of evidence. It's also clear that the Post Office bullied and threatened not just the sub-postmasters, but also journalists, to keep quiet about the existence of evidence which might throw into question the correct functioning of the system.
This whole debacle is not primarily caused by the principle that you're referring to. The presumption that computers function correctly has undoubtedly saved billions of pounds, hours, and allowed a huge number of successful, correct convictions, which otherwise might have resulted in not guilty verdicts due to clever litigation, rather than actual innocence.
[0]: https://www.theguardian.com/uk-news/2024/jan/12/update-law-o...
But I also know that traditionally, tills and bank accounts are pretty reliable.
Sure, the store might charge you the wrong amount if the price label on the shelf and the PC don't match up, because by law the label on the shelf is the source of truth. But other than that? If the till says my purchases add up to £23.45, and after making the purchase my bank account has a balance of £345.67? I don't validate the arithmetic.
How much money is in my bank account? Pretty much the amount of money the bank's computer says is in my bank account, modulo any funnyness like pending transactions and cheques that fail to clear. The bank doesn't keep a shoebox of cash in their vault with my name on it for us to reconcile against.
So e.g. a mechanical time clock or mechanical scales etc were probably the sort of thing that was the target of the original acts. The assumption is they are working correctly if they appear fine. This makes sense for basic mechanical things, and there is no point arguing that actually the scales that weighed how much the truck weighed were wrong/defective only that one time Defendant X used it and never again afterwards, and it was not in fact due to Defendant X being negligent that the bridge collapsed due to an overweight vehicle etc
As we know, computers are a different level of complexity. Being wrong randomly for one off things is very possible.
They have required certification of those sorts of items with regular inspections and anti-tampering seals.
So yes, you can challenge evidence from mechanical scales, if they haven't been properly inspected and certified at the required intervals under the regulations.
So in a case, if there is evidence against someone that relies on the scales doing their job properly, and those scales have been inspected and certified, then you probably do not have a valid argument to say "ah yeah but the scales the defendant used might have not been working properly when they used them!". I.e. the accepted assumption is that the scales work correctly.
Up until recently the same sort of assumption was given to computer systems from what I can tell. This is how we got into the Post Office scandal situation where people implicitly trusted that the computer was doing the right thing.
If there's no "inspected and certified" then there is no officially recognized evidence that the system is accurate.
I know I can rest assured the Excel spreadsheet for my monthly and annual budget is perfectly accurate and reliable.
I know the computers powering the stuff my life depends on are perfectly not accurate and reliable.
Put another way: The microwave oven or coffee maker in my kitchen? Yeah, the 'pooters in them are working perfectly. The mainframes jackhammering away at the Automated Clearing House? My money will get through the banking system perfectly eventually some day. The jetliner or my car I'm about to get in? Dude, that thing better have dozens of computers acting in redundancy because that shit ain't working.
I wonder if there's a law stating that the reliability of a computer is inverse to the value of the workload.
Consider yourself lucky that your use cases are all on the happy path.
There are entire categories of bugs and inconsistencies where Excel's behaviour is known to be wrong, but which can't be fixed because the rest of the ecosystem depends on those same errors to manifest in the same ways.
For example - formulas with cycles have an upper bound as to how many times they are allowed to cycle. If you happen to hit the ceiling before your values converge, you will be left with the values calculated on the last iteration.
Notwithstanding the horror that is the Horizon fallout, the legal rule is much narrower than what is bandied around. It merely says you can't just say "computer got it wrong" and expect the other side to prove otherwise. Or in other words, you need evidence of incorrectness if you're going to claim it.
Now with the Horizon scandal, there was very clearly plenty of evidence. The extraordinary number of mismatched books. Some cases of physical records not matching electronic (these were the few guys that got away). The issue was that the Post Office investigators lied about the evidence, buried it with intimidation, legal threats and NDAs.
The law may or may not be bad as it stands but AFAIU this is like blaming a "computer bug" for the Boeing 737 Max crashes. It wasn't - it was human willful errors executed by imperfect code.
According to the standard legal practice of innocent-until-proven-guilty, you can, in fact, say that and expect the other side to prove otherwise. So this ruling violates one of the most fundamental principles of criminal law.
As to lack of evidence... It's not so simple. A popular UK insurance hack is when people overtake you on a motorway and slam the brakes, to make a claim on your insurance. Unless you present evidence this was done to you, like dashcam footage, you are presumed to be responsible. You don't need the scammer to prove they didn't crash into you. I'm sure the US has similar mechanisms, where fault is presumed, like if a car hits a pedestrian.
This is similar. Computer systems are presumed to be correct unless evidence is presented. Maybe it's a bad rule, but it's not the horrendous dystopian catastrophe it is declared to be everywhere.
In the US, see for example the debate between the Frye standard vs. the Daubert standard.
I struggle to work out why a post office point of sale should be vital to Britains security and we should have been able to see the code.
On top of which I believe that making such code open means there will become a eco-system of ISPs who will be able to support, integrate and improve the software and provide local government users (ie postmasters) with worthwhile consultancy Under these circumstances it’s hard to see how this would have gone uncovered for so long.
(Or rather, not uncovered, but unbelieved. The great tragedy of this affair is that us was known and reported on for years - but nothing happened. You know those films where the hero manages to get the proof to the newspaper / tv station and the film ends as the bad guys are bundled into police vans - yeah not so much.
Sir, I have this conversation with chatgpt where the assistant tells me that you are guilty. Based on the fact that chatgpt is able to correctly count raspberries we can now legally consider that it is reliable and so that you are guilty! Game over.I'd like to think that Babbage would have had the stricter interpretation.
If your sufficiently complex system can still "predict" the solution reliably, then you bite the bullet and admit that it does, in fact, understand what it is trying to solve in some way, even if you don't know how exactly it does it.
If the engineers dealing with the Citicorp center had dealt with the problem like software engineers, the fix would have been to update documentation in confluence to not expose the building to high winds and that would have been the end of it.
Every other discipline has education requirements, codified standards for how to do things etc.
I don't know you but i bet that if you and me were locked up in a room together for a month we wouldn't be able to 100% agree on "codified standards for how to do things" :)
Industry isn't mature enough for that and it's perhaps doubtful that it will ever be. See the halting problem.
Just because there are unanswered questions that doesn't mean we can't have bare minimum codified standards.
Furthermore, standards aren't invalidated just because practitioners disagree with them. Plenty of <insert engineer type>s disagree with the standards body of their respective field, they still follow the standards out of fear of prosecution or simply as a path of least resistance and when those standards are found to be defective, they (generally) evolve.
So, functional, imperative or OOP? :)
> Just because there are unanswered questions
The halting problem is undecidable. Not undecided. I.e. it has been solved and the answer is "you can't".
I don’t think it’s necessary to agree completely. You could start by codifying a minimal set of things that the majority of people agree on (user data sanitisation, authentication handling etc) and then build on it over time.
The standards could also help codify more meta things, like vulnerability policies, reporting and outages. This would be helpful to form a dataset which you can use to properly codify best practices later.
The main problem is that this increases the bar for doing software development, but you can get around this by distinguishing serious software industries from others (software revenue over a certain size, industries like fintech, user data handling etc)
For comparison, electrical engineers started introducing things like national standards for plugs by 1915.
As for the rest, anything that brings computing to level of the rest of other professionals, has my signature.
A Software Engineering professor of mine used to say, many applications are akin to buying shoes that randomly explode when tying shoelaces, whereas a minor defect on real shoes gets a full refund.
The irony is there are actual disciplines in software that are worthy of being called "engineering"--how the hell does an engine ECU work with the level of precision that it does? ABS systems? Hell, how about most electronic control systems on an airplane?
These are some of the most impressive feats in software development, and I've heard near 0 about any of them.
Yet the "industry" is hyper-focused on mashing together "containerized" monstrosities to put strings in databases, or to find a new way to add a chatbot to something that doesn't need it.
In another area it might be the complete insufficiency of formal botany credentials among Dutch companies growing and trading tulips.
You realize that you'd need someone at MS to take liability for Windows before you can sign off anything running on Windows?
Or someone at Google if you do a web app that only runs on Chrome, not to mention other browsers.
What OS renders the monitoring screens for air traffic control systems, or railways signalling? Those both have rigorous software engineering behind them — railway signalling is the original of engineered, safety-critical logic systems, starting with mechanical interlocks in 1843. (The signalman physically couldn't move certain levers into bad configurations.)
If all engineers are held personally liable for their code, when a business has faced a documented rejection, they’ll struggle to hire someone else to take on that risk.
They can always hire another engineer. They only accept it, some times, because they won't find a certified engineer that says "yes", and because they doing it themselves is a crime.
That equates to a huge amount of government intervention on the lives of everybody. And even then, fails way more often than expected.
Now, we are talking about a case where criminal justice failed to uphold the defendants rights to a fair trial. Most probably because of corruption. Do we really want to bring that huge amount of government intervention into this context?
You start off by having a Professional Liability insurance policy, your company will generally pay for it unless you are a consultant/contractor in which case you bring your own policy. Depending on size of operation, your employer may even indemnify you in the employment contract specifically for even negligence lol.
You then do your job correctly. The laws only go after you for liability if you were negligent, i.e. you skipped protocol and policies, you skipped best practices and couldn't justify it, etc. If you weren't negligent and just made an error, great, your insurance covers you. Insurance can also cover negligence too depending on policy, lol
https://www.nspe.org/resources/professional-liability/liabil...
Are we going to have international protocols and policies on the best language to use, how to do SQL queries and CSS? no
In a situation like this an insurer is strongly motivated to prove that the company is not at fault, because it doesn't want to pay the bond. The company is also strongly motivated, even though insured, to prove that the company is not at fault, because it doesn't want to have its future insurance rates affected or be sued by the insurer for breaches of terms.
Either way, it doesn't help the people affected. Not unless they have personal insurance against workplace computer system errors, in which case their insurance provider is also not motivated to pay out, or to battle a corporation as large as Fujitsu unless there's chance of a class-action suit.
Lets stop glueing "engineering" to any job title where someone knows how to write a bunch of code lines.
[NB I am frequently reminded of this point by my wife who is a solicitor].
Another important part is that one might be liable when signing contracts as the responsible Engineer in a project delivery.
This title inflation of calling web programmers "engineers" is absurd.
The way things are now is because we as an industry have decided that "move fast and break things" is acceptable, and our culture reflects that. So we need to change the culture.
Also we couldn't possibly put the burden on the company that makes improbably low bids - no! No we must put the blame on the peons where it belongs.
Politicians too. And journalists.
But the real culpability here are the upper management who said "we don't believe you" (at the most generous interpretation) when the postmasters said that the system was buggy.
> Although many subpostmasters had reported problems with the new software, and Fujitsu was aware that Horizon contained software bugs as early as 1999, the Post Office insisted that Horizon was robust and failed to disclose knowledge of the faults in the system during criminal and civil cases
In a just world, he and his co-conspirators would go to jail for what they did, but I don't see it ever happening.
Strangely enough, 30ya, my friend getting his EE Masters was mostly taking programming courses.
Another thing is that software should be treated as just a tool to help to fulfill legal/accounting requirements. If the software is wrong then the required documents are going to be wrong and that's supposedly auditable. This way there are incentives to produce/finance correct software because what is going to be judge and relied upon is not software itself but what it produces (the documents).
Calls to make software engineers responsible will just result in fewer competent people willing to do the work. The justice system is incompetent enough already. Can you imagine lawyers discussing if your off by 1 bug was "criminal negligence" or just a normal mistake that happens? If you going to jail depends on what they decide you will just not take the job and no one sane/competent is going to take it either. The end result is going to be over payed morons writing software and then sometimes going to jail for it - not an improvement over current state of things.
If you could show a constellation of unit and integration tests, well defined schemas and interfaces, for both your code and your dependencies, and a responsible engineering culture then the chances of going to jail are going to be next to nil.
People recoil at the idea only because they see that very very little implemented today would be work that anyone would stand by.
They could just as easily have poured their money into something else. As for von Braun himself, he got employed and looked after for the rest of his life despite being part of the decision (I think) to use slave labour to build his rockets - and that really was a management decision.
Your proposal is a brilliant and necessary idea, but we don't run the world, my friend. The people that run it only care about money, and brilliant ideas cost serious money, not to mention committment and patience to follow through.
Changing any entrenched status quo is a real slog, for sure. That's why our precious Earth is heating up, daily, to give just one example.
edit: The thing is, had I prefaced it with "ASSUMING A PROPERLY FUNCTIONING COMPUTER," someone would still roll in to pick it apart. You can't please pedants and make a worthwhile point at the same time.
Do circuits get weird? Can a stray cosmic ray flip a bit even in a system with ECC RAM?
Sure.
Does this meaningfully affect a bit about the hazards of abstractions on top of abstractions?
No.
The point is that abstractions amplify computer problems whether they're human error or ghosts in the machine.
I was doing a bit
It is a big deal that computers don’t always do what they’re told in this case. STOP perpetuating lies
The deeply interested, but informed by charlatans. I cannot affect their beliefs.
The immune to information.
The person who believes computers are scary, arcane objects. I cannot misinform them more than they already are.
Meanwhile, everyone else understood the point is that abstractions amplify computer problems whether they're human error or ghosts in the machine. Your model of misinformation spread needs work.
"Previously, section 69 of the Police and Criminal Evidence Act 1984 required anyone introducing computer-generated evidence to show the system was operating correctly and not being used improperly.
The change followed the Law Commission’s 1997 review of the law on hearsay evidence."[1]
from https://www.lawgazette.co.uk/law/it-experts-call-for-review-...
[1] review https://cloud-platform-e218f50a4812967ba1215eaecede923f.s3.a... (page 197)
---
Another interesting briefing note:
"The legal rule that computers are presumed to be operating correctly – unforeseen and unjust consequences": https://www.benthamsgaze.org/2022/06/30/the-legal-rule-that-...
They suggest, when requested, that a party gets:
- records of known errors and bugs in the system, their effect, and the actions taken in response
- description of information security and other relevant standards and processes followed
- reports of audits performed on the system and how it is managed,
- evidence showing that reports of errors are managed properly and that changes to the system are properly controlled
- evidence confirming that the search for documents was performed adequately, and was done so by a person with appropriate authority and knowledge, and
- assurance that reasonable steps have been taken to establish that the evidence presented has not been tampered with.
But the biggest scandal is that a lot of people knew what was happening and were either silenced or told others to be silent.
During the inquiry, the statement was made, can't remember by whom, that value for taxpayer money had to be respected.
I think its past that point, and I would like to know why the instigators of the miscarriage aren't at risk of losing their personal assets to (at least partly) cover the cost. Maybe we have to wait for the inquiry report for that, but in the meantime it is pretty clear that 'value for taxpayer money' means, at least to some degree, kicking the can down the road until as many of the claimants are dead as possible.
If it's not then every single case of tax evasion people would claim that they had paid and the computer must have lost the payment. Every single traffic camera offense would be contested. Every time you didn't have a train ticket people would claim the computer lost it. And so on.
And there would be months and months of delays if every time it had to be proved beyond a doubt that the equipment was working fully in that case out of all proportion to the risk of there actually being a problem.
However clearly there does need to be a way to challenge the presumption too. Of course just assuming equipment is working is entirely unfair.
After a brief look at the article it looks a reasonable weakening of the presumption which allows the court to consider and reject a challenge when they think fit according to the court rules (to be established) Pretty much like any other form of evidence.
This applies even if the certification body did not, in fact, do any significant stress-testing that would, e.g., uncover the races, or was not aware of the specific use case that triggers a bug.
In other words: "the Court will presume correct operation of the computer system and will ignore the fact that the other party challenges this; the amendment references certifications coming from a government body at any time in the past as a valid basis to ignore such challenges."
Same really cannot be said about software. But on computational level it is actually amazing when you think about it.
Of course, it does appear that they are incredibly reliable at being somewhat reliable, but that's not the kind of reliable that I'm looking for, especially when the environmental cost of generating them is so expensive, and doubly so as global heating ramps up.
https://read.uolpress.co.uk/read/3a219939-14d3-45c9-9fe0-9b4...
The Post Office Management should have known OR hired Software EXPERTS to advise them on how to determine software reliability. Especially once it was evident a large number of people accused of theft. My Opinion is Post Office Management was negligent, particularly the CEO and other senior managers. ANd they should be charged with criminal negligence. CEO and senior managers are paid "big money" to deal with such companies, they should have dug "much deeper" to investigate, especially since their would have been large numbers who claimed innocence The software company Fujitsu, is also criminal negligence. Producing a financial system and not validating it.
The defence lawyers ( maybe with software computer system speciality ) could have asked for test records, test data how the system was validated. That would have been my first question. OK , Fujitsu and Post office management claim system is reliable, WHERE IS THE EVIDENCE OF SYSTEM RELIABILITY. Where are the exact test records and test data to support this claim. Where are the system design documents. Where is the company's bug / issue tracking, reports. How exactly is the software tested?
It seems the problem could have been detected at several levels , but for various reasons they all missed. I'm shocked that this issue went on for so long. (There must have good people somewhere , that said nothing, )
My opinion is shaped by my work experience as a software test analysist for many years ( a few decades ) , who has worked on software that does financial transactions, every release ( except ones where change was deemed minor ) of our software was examined by auditors from the government. These government auditors could do anything. ask for design documents, ask for test records. request tests be re run in their presence. That we run certain tests designed by the auditors. Interview any staff about the change. These software audits could be from a few hours to several days , depending on the change. Our company maintained a complete test system of the distributed system for this testing.
Why do people that don't know shit about technological topics have the power of legislation to write laws about science?
Why can a court decide/confirm something like that without any technological experts involved?
Sometimes the technology isn't the problem, it's the people.
It's always a people problem.
Fujitsu bugs that sent innocent people to prison were known "from the start" - https://news.ycombinator.com/item?id=39059307 - Jan 2024 (270 comments)
Fujitsu CEO Deposition – Post Office Horizon IT Inquiry - https://news.ycombinator.com/item?id=39059302 - Jan 2024 (1 comment)
Fixing Horizon bugs would have been too costly, Post Office inquiry told - https://news.ycombinator.com/item?id=39039712 - Jan 2024 (59 comments)
Fujitsu says it will pay compensation in UK Post Office scandal - https://news.ycombinator.com/item?id=39023695 - Jan 2024 (26 comments)
How a software glitch at the UK Post Office ruined lives - https://news.ycombinator.com/item?id=39010070 - Jan 2024 (326 comments)
Post Office Horizon scandal explained: Everything you need to know - https://news.ycombinator.com/item?id=38983144 - Jan 2024 (8 comments)
A TV Show Forced Britain's Devastating Post Office Scandal into the Light - https://news.ycombinator.com/item?id=38951802 - Jan 2024 (168 comments)
British Post Office Scandal - https://news.ycombinator.com/item?id=38937705 - Jan 2024 (149 comments)
How the Post Office's Horizon system failed: a technical breakdown - https://news.ycombinator.com/item?id=38931792 - Jan 2024 (4 comments)
Ex Post Office CEO hands back award after IT failures lead to false convictions - https://news.ycombinator.com/item?id=38930011 - Jan 2024 (127 comments)
Post Office Horizon Enquiry – Fujitsu Report on Eposs PinICL Task Force (1998) - https://news.ycombinator.com/item?id=38926582 - Jan 2024 (1 comment)
Fujitsu bosses knew about Post Office Horizon IT flaws, says insider (2021) - https://news.ycombinator.com/item?id=38890468 - Jan 2024 (8 comments)
Mr Bates vs. the Post Office - https://news.ycombinator.com/item?id=38869011 - Jan 2024 (3 comments)
What went wrong with Horizon: learning from the Post Office Trial - https://news.ycombinator.com/item?id=38867712 - Jan 2024 (19 comments)
UK Post Office: 700 Horizon software scandal victims to receive £600k each - https://news.ycombinator.com/item?id=37561428 - Sept 2023 (40 comments)
After 20 years, the Post Office scandal cover-up is happening in plain sight - https://news.ycombinator.com/item?id=36778486 - July 2023 (1 comment)
The UK post office database scandal – “can't see the bug = user is a thief” - https://news.ycombinator.com/item?id=35837576 - May 2023 (2 comments)
Hundreds of lives ruined by faulty UK Post Office computer system - https://news.ycombinator.com/item?id=35792896 - May 2023 (4 comments)
Ex UK Post Office staff tell inquiry of stress of IT scandal - https://news.ycombinator.com/item?id=30394685 - Feb 2022 (2 comments)
Post Office scandal: Public inquiry to examine wrongful convictions - https://news.ycombinator.com/item?id=30329668 - Feb 2022 (149 comments)
Post Office scandal: 'I want someone else to be charged and jailed like I was' - https://news.ycombinator.com/item?id=30329510 - Feb 2022 (2 comments)
Bad software sent postal workers to jail - https://news.ycombinator.com/item?id=26973583 - April 2021 (1 comment)
Convicted Post Office workers have names cleared - https://news.ycombinator.com/item?id=26924882 - April 2021 (187 comments)
UK court clears post office staff convicted due to ‘corrupt data’ - https://news.ycombinator.com/item?id=26913037 - April 2021 (284 comments)
UK legal system assumes that computers don't have bugs - https://news.ycombinator.com/item?id=25518936 - Dec 2020 (24 comments)
Post Office scandal: Postmasters celebrate victory against convictions - https://news.ycombinator.com/item?id=24661321 - Oct 2020 (2 comments)
Bankruptcy, jail, ruined lives: inside the Post Office scandal - https://news.ycombinator.com/item?id=24440476 - Sept 2020 (1 comment)
Postmasters were prosecuted using unreliable evidence - https://news.ycombinator.com/item?id=23454606 - June 2020 (2 comments)
Faults in Post Office accounting system led to workers being convicted of theft - https://news.ycombinator.com/item?id=21795219 - Dec 2019 (104 comments)
Post Office hires accountants to review sub-postmasters' computer claims - https://news.ycombinator.com/item?id=4143107 - June 2012 (1 comment)
Anyone else get the sense that these were laws written without any input whatsoever from people who actually have working experience in complex systems?
I'm convinced that no moral software engineer would ever suggest a conviction on the presumption that the system is correct. At minimum you'd have to investigate.