IMHO, the most concerning sign about software engineering practice isn't exactly "bloat", but the <i>inability of the industry to do anything securely</i>.<p>Consider every software security update to be a bridge falling down, due to incompetence.<p>In this case, the fault isn't so much individual incompetence, as collective incompetence of the field. The ecosystem is toxic, as are conventional practices, as are market incentives. Individuals might be incompetent on top of that, but the situation is nigh impossible for competent ones as well.<p>And there are no professional engineer licenses to pull, nor few individuals to send to jail.