News: 1610192712

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Buggy code, fragile legacy systems, ill-conceived projects cost US businesses $2 trillion in 2020

(2021/01/09)


Shoddy software cost the US an estimated $2.08tr in 2020, according to the Consortium for Information & Software Quality (CISQ). That's down slightly from a revised 2018 total of $2.1tr but still isn't anything to brag about.

In its [1]2020 report , The Cost of Poor Software Quality in the US, the Massachusetts-based standards group co-founded by the non-profit Object Management Group and Carnegie Mellon University's Software Engineering Institute (SEI), identifies three major cost sinkholes.

[2]

Unsuccessful IT initiatives and software projects are estimated to have cost $260bn in 2020, up from $177.5bn in 2018. Poor quality in legacy systems is said to have eaten up $520bn, down from $635bn in 2018. And operational software failures – bugs – took a toll of $1.56tr last year, significantly more than the $1.275tr flushed away in 2018.

"The losses due to operational failure in the US alone are staggering," said Dr. Bill Curtis, executive director of CISQ, in a statement. "It just takes one major outage or security breach to eliminate the value gained by speed to market. Disciplined software engineering matters when the potential losses are at this scale."

The consequences of poor quality software are evident in various examples cited in the report, such as the [3]two serious software bugs that prevented Boeing's Starliner from docking with the International Space Station in December, 2019, and put the spacecraft at risk.

Boffins debunk study claiming certain languages (cough, C, PHP, JS...) lead to more buggy code than others [4]READ MORE

The incident resulted in Boeing taking a $410m charge in Q4 2019, which looks rather insignificant compared to the [5]$2.5bn the company will pay to avoid fraud prosecution related to the deadly crashes of two Boeing 737 Max aircraft, also linked to bad software.

Why is the situation so grim? The report argues there's an IT talent shortage, a claim [6]others have made as well.

"There are simply not enough good software developers around to create all the new and modified software that users need," the CISQ report says.

"Given the indirect as well as the direct contribution of software to the economic base of most industrialized countries, and considering the ways in which software can amplify the powers of the individual/teams/organizations, we cannot allow this situation to continue."

The report claims that just two percent of the worldwide population can code and that the need for developers is expected to grow by 24 per cent over the next seven years. And it notes that the US Bureau of Labor Statistics says US software developer jobs will increase at a rate of 22 per cent over the next decade.

To reduce the number of operational failures – the largest problem segment by fair – the report calls for better software defect detection and remediation of identified vulnerabilities. It asks individual developers to take responsibility for prioritizing software quality and it urges organizations to promote a culture that supports software excellence.

[7]

"Producing quality products and systems makes good business sense, but what that means must be well-known in your organization," the report concludes. ®

Get our [8]Tech Resources



[1] https://www.it-cisq.org/the-cost-of-poor-software-quality-in-the-us-2020-report.htm

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x250%7C300x252%7C300x600&tile=3&c=33X-nhIw6IJMeSv3qsPm9J9QAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2020/02/10/more_software_errors_beset_boeings_calamity_capsule/

[4] https://www.theregister.com/2019/01/30/programming_bugs/

[5] https://www.theregister.com/2021/01/08/boeing_737_charges/

[6] https://www.theregister.com/2020/10/30/cyberstart_hacking_challenge/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x100%7C300x250%7C300x251&tile=4&c=44X-nhIw6IJMeSv3qsPm9J9QAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://whitepapers.theregister.com/

Shortage? What shortage?

Anonymous Coward

What happened to all those Indian hordes of Java programmers that have been flooding this country for the last 30 years or so? Does it mean it's been all for nothing?!

Blame the management

Danger Mouth

Just been let go by a US bank. They have lost all respect for any IT skills/aptitude and have the attitude that anyone can code, as long as it's all API based or whatever weed enhanced fad has been dreamt up in California this week to sell more books. All passwords being replaced with trusted authentication for example. Even where its blindingly obvious that it leaves all your data sources open for abuse.

I fail to see the problem

cschneid

While the article qualifies the usual assertion of a developer shortage by noting a shortage of good developers, I simply cannot see the difficulty.

We all know the definition of a good developer, it's someone who delivers on time and on budget. Accomplishing this goal merely requires a calendar and a calculator, both of which are included with Microsoft Windows and all the other (admittedly minor) players in the desktop and server space.

The CASE tool renaissance of the late 1980s taught us that the act of writing code is so trivial a task that it can be automated. The Y2K crisis taught us that anyone can engage in the act of writing code having augmented their keyboarding skills with a "Learn language in n [hours|days|weeks]" book.

Disabusing decision makers of the above load of equine excrement is going to be difficult. In the middle of the last decade of the previous century I recited to my boss that old saw about "cheap, fast, or efficient - pick any two." He replied that he'd heard that one, and he wanted all three. I took another offer soon after. And no lesson was learned.

The mindset that software developers are resources to not just be used, but used up is pervasive. That software development and project management are othogonal remains unknown to those who design org charts and compensation plans.

This is not a problem that gets fixed by adding more developers, no matter how good they are.

Re: I fail to see the problem

amanfromMars 1

The core new clear problem to see is always the same and is something which cannot be fixed, but that doesn't stop deaf, dumb and blind and intellectually challenged systems administrations from tasking future developers and systems administrations with the same impossible and increasingly rapidly eventually inescapable and personally identifying self-destructive task ...... the ever more complicated defence of the indefensible that constantly inspires and feeds ever more stealthy and increasingly damaging and deadly attacks.

The simplest of complex solutions is easy to see and share ....... Stop trying to fix something impossible to fix and just simply decline to continue to defend the indefensible and inequitable and iniquitous.

IT aint FCUKing Rocket Science ...... Greater Common Sense.

I can code (program)

hayzoos

I do not consider myself a developer, nor a coder, but a programmer. I will use a library if I know what it does inside, outside, topside...every side in every conceivable case I can muster. I will test it thoroughly as I test my own code. I am costly in both time and money, but strive to produce as correct code as I can; aka quality.

Many, many years ago, I was contacted to produce a payroll system for a company which had expanded from a single tax jurisdiction to multiple. They wanted the thing done in a month, they could not wait. I replied I would require no less than three months with one or two contingency until I could analyse the requirements. I did not get the job. Fast forward five years and I found out the "coder" the hire instead of me had delivered in two months instead of the agreed one. And, they were still working out bugs and had dozens of work arounds to process payroll including pre- and post- processing with a spreadsheet. They are now out of business.

The problem is unwillingness to pay for suitable quality. This goes far beyond software in IT. IT security is afflicted. It also does not help that the current trend of software is change for change sake and the abominations we are seeing is horrendous. There are losses due to abandonment of well reasoned user interface elements. How much time(money) is wasted when a form rejects input on submit when the input is formatted had been formatted in common form and only instructing the user of the expected form after the fact? Not really a rhetorical question, I just do not have the resources to make that determination. I can write a routine to transform input in common forms to the desired form for processing, I do not consider it to be time consuming or challenging. There are so many examples of poor programming, I could write an encyclopedia on the topic.

I agree training more developers is not the fix. The problem is deeper and requires a more complicated mitigation and is not likely to be accepted by those who make the decisions.

And if you are past a certain age ....

johnnorris10

Despite the shortage of developers, agencies will reject those of a certain age. Past that age, stay where you are (if you can) because get a new role will be tough. Of course, rejection for reasons of age is illegal so it's because "the company wants people to be there long term".

The mystery is why an industry filled with educated people decided to outsource hiring to the recruitment industry, an industry filled with people that are smart in a different way.

Context knowledge is missing

Andrew Williams

You cannot write decent code if you do not understand the context. As in, the business, the workflow, what the code should actually do.

How many coders (or anyone involved with coding) ever have that type of knowledge?

Bugger all is the answer. So, this naturally leads to the result that all you get is an “Agile” serving of bad spaghetti.

Think of prototypes as a funny markup language--the interpretation is
left up to the rendering engine.
-- Larry Wall in <199710221710.KAA24242@wall.org>