On Accountability
9 points by addison
9 points by addison
As someone who went to undergrad for a "traditional engineering" (civil), and took multiple ethics classes as part of the curriculum, I am keenly aware of the chasm between software engineering and these other fields.
When something causes harm in the traditional engineering domains, the company faces severe penalties, and a proper investigation is done to determine the cause of the failure.
One issue here is that its a lot more cut and dry in "traditional engineering domains" when something causes harm: people either are directly injured/killed, or large amounts of personal property are damaged in the best case. This is why these fields require licensure, so that someone's directly responsible for these decisions. We can all wish that people viewed code quality and the industry side effects as more of "someone's fault", but its just not as clear to a lot of people.
My understanding of engineering practices is indeed informed by my undergraduate degree. CS students received the same ethics and professionalism courses as engineering students, so it always struck me as night and day difference between CS and other fields.
My perspective may be skewed, but I feel like there's a significant number of people in software who have either dropped out of college, never went in the first place, or studied in a different field unrelated to engineering.
An engineer in a field regulated even lightly, whistleblowing the level of reliability indifference found in large for-profit software development companies, could probably get the company fined a fraction of its worth that would really be felt. Without that implicit threat, teaching ethics courses to individual contributors won't remove the things that management can easily impose.
Copyright licenses allowing to disclaim liability for software make sense for non-profit development and small companies, but not for software companies that got large. Right now they have the best combo: they get to abuse regulations (e.g. buying anti-circumvention laws), not subject to any effective regulation of their practices (maybe sometimes for some especially egregious monopoly abuse EU will fine someone), and are allowed to disclaim product liability.
I think just extending the undisclaimable product liability laws to software sold or rented or operated for profit after passing through hands of a company with more than 1000 employees or more than 100 million in revenue or more than 1 billion in funds would change a lot of things. Of course, there is a lot of lobbying money to prevent this.
I originally published this a week and a half ago, before we knew that OpenAI hacked HuggingFace. I figured it'd be worthwhile to share following my comment on the matter, as this really is part and parcel with my central claim: we need greater accountability for negligence and bad practices in software development.