― Ellen Ullman, Life in Code: A Personal History of Technology
(free with archive account, fascinating book, dedicated to "the first machine that can appreciate the gesture" https://archive.org/details/architecturemach00negr/page/n15/...)
There's some precedent for this: software in medical devices face strict regulations after incidents like Therac-25.
While most software might not carry the same life-or-death risks, data breaches are increasing in frequency and impact. We should at least be thinking about how we can improve our processes as an industry.
This exists in automotive, cf. ASPICE. And even more extensively in aviation.
And no, it doesn't help fight sprawl much sadly.
The HN crowd is mostly web and mobile and unaware how broad the software field is, even though software in safety-critical applications of course predates both.
Which is a shame because I'm pretty convinced that slowing down and having time to do those reviews is net-good in the (not-very-)long run. Much of the space (and bugs) in even a very well run large project are from accumulating gaps until nobody knows how things truly work - it takes time to eliminate them and end up in a simpler, smaller, more sustainable state.
If there was 'code', arguably, nothing would be built in the first place.
Engineering standards are built on piles of corpses. We’re lucky that most of the growth of our industry has been in non-life-critical areas.
But regulation and standards are coming eventually - shoddy code will just have to kill a few thousand people first.
Gatekeeping the entire industry isn't the answer unless you want to cripple it... but if someone wanted to issue regulations along the lines of "Don't steer your nuclear-powered aircraft carrier with a Windows app," I wouldn't object to that.
Pain ...
For the record I am going to eventually direct this app to the "normal" auth service and fix it all up, but man why is it this way???