back

by jtwaleson·2y ago·view on hn ↗
I'd argue that going for 0 failures in virtually any domain will lead to inefficiency. You need some failures to get the feedback that you've "under-engineered" something. Without failures, you can guarantee that you've over-engineered it.

In a similar vein, I think proper risk acceptance policies shouldn't say "security/safety is our #1 priority", just like a good SLA doesn't guarantee 100% uptime. When you set a 99.9% uptime SLA, make sure you're actually down sometimes. When you want efficient rockets, you have to see some of them crash.