Fallacy Catalog: 67 Techniques with Examples and Answers
Previous chapters analyzed fallacies one by one, with history and theory: Aristotle’s fallacies, formal fallacies, relevance, presumption, causality, cognitive biases. This chapter is a reference. Here everything is together and in one format, so you can find what you need in seconds, rather than trying to remember which chapter it was in.
Each entry has the same structure: what is substituted, mechanics breakdown, real-life example, the same technique in engineering practice, and the phrase used to respond. The order is by fallacy families, not alphabetically: what breaks in the same way is placed together.
How to use this
The catalog is useful exactly in two modes, and both should be named explicitly.
Identify. The conversation is going off track, there is a feeling of substitution, but no words for it. Then the catalog is read by fallacy families: first it is determined exactly what happened — attacked a person, derailed the conversation, broke the output schema, jumped between stages, made a causality error or substituted a word. Within a family, the needed name is found in a minute.
Check yourself. Your argument before sending is processed by the family it most often falls into. The most useful family for an engineer is the family of causes and data: that’s where conclusions like “we released a version — errors increased — therefore, the release is to blame” live.
There is also a third mode, harmful: to look for a label in someone else’s speech in order to close the conversation. It breaks the very purpose of the list, and error number 67 is about this.
What an error name proves and what it does not
The found fallacy name does not refute the thesis. It says only one thing: this specific argument does not prove it. The claim returns to the “not demonstrated” state — not “false”. If after “this is ad hominem” the conversation is considered won, the same substitution has occurred as with the interlocutor, only from the other side.
Second, to keep in mind: several catalog errors have legal versions. A slippery track becomes a valid argument when the transition mechanism is named. An appeal to authority is legal when the expert speaks within their qualification and does not replace the checked basis. An analogy is a working tool; the error begins with transferring a non-essential feature. Therefore, in records of these errors, the boundary is clearly drawn, not left to the reader.
Catalog with filters, search, and fallacy family map lives as a separate page: logical fallacies space. The data there and here are the same, so the reference book and the page cannot diverge.
Six fallacy families at a glance
Attacking the person
What gets examined is not the argument but whoever made it: where the position comes from, the tone, the biography, the right to speak.
1. Ad hominem. The person who made the claim gets judged instead of the grounds the claim rests on.
4. You too (tu quoque). A demand is declared void on the grounds that whoever makes it breaks it himself.
9. Straw man. The position is replaced with a version that's easier to refute, the replacement is refuted and the question declared closed.
24. Genetic fallacy. A claim is accepted or rejected by where it came from, not by what it says.
48. Psychologist's fallacy. Your reading of someone else's state is passed off as the state itself, and the argument goes on against the reading.
55. Circumstantial ad hominem. The claim is declared false because the author's position or gain gives him a motive to say it.
56. Tone policing. The answer on the merits is postponed by pointing at the form, the volume or the emotion of what was said.
57. Guilt by association. A claim or a thing is discredited through whoever else shares or uses it.
58. Appeal to accomplishment. The right to judge is derived from a track record: achieve something first, then talk.
59. Courtier's reply. Criticism is dismissed by pointing out that the opponent hasn't studied the subject enough — without answering the criticism itself.
62. Bulverism. The falsity of the position is treated as already established, and the speaker goes straight to explaining how the opponent arrived at it.
Changing the subject
The point under dispute is swapped for another one — more convenient, louder, or impossible to object to without looking bad.
3. Red herring. Instead of an answer another, more winnable topic is introduced, and the discussion drives off after it.
7. Loaded question. The question is built so that any direct answer confirms an unverified presupposition.
18. Appeal to emotion. The place of the missing grounds is taken by an induced feeling — fear, pity, shame or ridicule.
38. Quoting out of context. The fragment is kept word for word, the condition, the qualifier and the scope are dropped — and the meaning shifts to a convenient one.
41. Conflict inflation. A local disagreement is stretched into a total one, and instead of one disputed point the conflict at large gets discussed.
44. Appeal to morality. Instead of how things are, what gets discussed is how they ought to be.
51. Thought-terminating cliché. A ready-made stub phrase closes the topic without answering a single question.
53. Appeal to the stone. The claim is declared absurd without a single argument brought against it.
65. Two wrongs make a right. Your own dubious move is excused by someone else's identical one — and theirs is what gets examined.
The shape of the inference
The form of the reasoning itself breaks: a premise passes for a conclusion, an effect for a cause, ignorance for proof.
6. Special pleading. The general rule is accepted, but an exception is introduced for one's own case with no independent criterion.
10. Circular reasoning. The conclusion is used as its own grounds — directly or through a chain of renamings.
15. Affirming the consequent. From “if A then B” and an observation of B, A is inferred, though B can have other sufficient causes.
17. Shifting the burden of proof. One person advances the claim, the other is required to prove it false.
26. Affirming a disjunct. From “A or B” and the affirmation of A, B is inferred false, though the “or” may be inclusive.
29. Appeal to ignorance. Absence of proof is passed off as proof of absence — or the other way round.
33. Denying the antecedent. From “if A then B” and “not A”, “not B” is inferred, taking a sufficient condition for a necessary one.
46. Proof by assertion (repetition). The claim is repeated unchanged and more insistently instead of being given grounds.
54. Irrelevant conclusion (ignoratio elenchi). What gets refuted isn't the claim that was advanced, and the original is declared refuted.
64. The “I am entitled to my opinion” fallacy. The right to state an opinion is passed off as grounds for holding the opinion true.
66. Vacuous truth. A statement is true only because no case capable of refuting it exists — and it sounds like substantive confirmation.
67. The fallacy fallacy. From the argument for a claim being bad it's inferred that the claim itself is false.
Generalisation and boundaries
An illegitimate jump between levels: from the particular to the general, from a part to the whole, from a continuum to two options.
2. Hasty generalisation. A conclusion about a whole class is drawn from a few cases that simply happened to be at hand.
5. Slippery slope. The inevitability of the last step is derived from the first, without a single intermediate transition being shown.
8. False dilemma. The space of options is narrowed to two, although a third is available and simply was not named.
13. Fallacy of composition. A property of every part is ascribed to the whole, although the assembly has a behaviour of its own.
14. Fallacy of division. A property of the whole is ascribed to each of its parts.
19. No true Scotsman. The counterexample is not refuted but retroactively removed from the class by the word “true”.
25. Middle ground fallacy. From the fact that two positions are extremes it is concluded that the truth lies exactly between them.
30. Continuum fallacy. From the absence of a sharp boundary between states it is concluded that there is no difference at all.
32. False analogy. From similarity in one feature, similarity in another is inferred, although there is no link between the two features.
39. False equivalence. Two cases are declared identical on a shared feature, ignoring the difference in scale, frequency and consequences.
45. Nirvana fallacy. A working solution is rejected for not being perfect, without being compared to the alternative actually available.
Causes and data
A wrong conclusion drawn from observations: about a cause, about a probability, about a sample. This is the family that incident reviews break on.
16. Anecdotal evidence. One memorable case is put in place of data on how often it actually happens.
20. Texas sharpshooter fallacy. The target is painted after the shot: the hypothesis is fitted to a random cluster already spotted in the data.
21. Cum hoc ergo propter hoc. From the fact that two quantities move together it is concluded that one causes the other.
28. Sunk cost fallacy. Past unrecoverable investment is offered as a reason to continue, although the decision depends only on the future.
34. Post hoc ergo propter hoc. From the fact that B happened after A it is concluded that A caused B.
36. Ecological fallacy. A property of a group, computed as an average, is carried over to each of its members.
40. Historian's fallacy. A past decision is judged with knowledge the person deciding did not have at the time.
42. Incomplete comparison. A comparative claim is presented without the second term of the comparison, without a baseline and without the conditions of measurement.
43. Gambler's fallacy. An independent random process is expected to compensate for the run that came before.
47. Cherry picking. Only the confirming part of the available data is shown, and the equally weighty part that refutes it is passed over.
50. Retrospective determinism. From the fact that an event happened it is concluded that it could not have failed to happen.
52. Fallacy of the single cause. For an outcome with several interacting causes one is named, and the explanation is treated as finished.
Language and authority
The argument rests not on the claim but on the word it was named with, or on the source it came from.
11. Appeal to authority. Instead of a ground, the name of whoever said it is produced.
12. Appeal to nature. From the fact that a thing has been called “natural” it is concluded that it is good.
22. Argument from incredulity. “I cannot picture it” is presented as “it cannot be so”.
23. Equivocation. The same word means different things in two premises, and the conclusion uses both meanings at once.
27. Appeal to tradition. “It has always been done this way” is substituted for a ground why it should be done this way.
31. Moving the goalposts. A condition was named, the condition was met — and then the thing under discussion is quietly replaced with another.
35. Definist fallacy. An evaluation is built into the definition in advance, and the argument is won before anyone has looked at the subject.
37. Etymological fallacy. From the origin of a word it is inferred what the thing it names is obliged to be.
49. Reification. An abstraction is treated as a thing with a will, a location and demands of its own.
60. Appeal to consequences. The unpleasantness of the consequences is passed off as the falsity of the claim, their pleasantness as its truth.
61. Appeal to novelty. “This is newer” has been substituted for “this is better”.
63. Chronological snobbery. A claim is rejected for being old — as if a later era had already refuted everything that came before it.
Full catalog
Further the same, but in full: with a walkthrough of the mechanics, examples and answers.
Attacking the person
What gets examined is not the argument but whoever made it: where the position comes from, the tone, the biography, the right to speak.
Ad hominem
argumentum ad hominem · ad hominem · argumentum ad personam
The person who made the claim gets judged instead of the grounds the claim rests on.
A claim and its author are two different things to check. Ad hominem swaps the question “what does the claim rest on” for “what sort of person said it”. Facts about the person can be relevant — when the claim rests on his testimony, his qualification or his interest — but then the conclusion is limited to trust in the source and reads as “this needs independent checking”, not “the claim is false”. The tell: remove the characterisation of the author and nothing is left of the objection.
Claim. The utility bill charges for water twice.
Move. You always mix up numbers — and now you're the one counting.
Why it is a fallacy. Past arithmetic mistakes don't change what's on the bill: the lines are either duplicated or they aren't, and anyone who opens the bill can see it, whoever noticed first.
At work. In code review a comment about a race condition on a shared cache is closed with “you've been here three months, you haven't seen our load”. The reviewer's tenure doesn't undo the missing synchronisation: either a test with two concurrent writes reproduces the race or it doesn't.
What to answer. “Suppose I get this wrong all the time. Look at these two lines — what's wrong with them?”
You too (tu quoque)
tu quoque · argumentum ad hominem tu quoque · appeal to hypocrisy
A demand is declared void on the grounds that whoever makes it breaks it himself.
A person's inconsistency is a fact about the person, not about the rule. That someone doesn't follow his own advice supports at most a verdict on his discipline; the grounds for the advice stay exactly where they were. The move isn't useless: in an argument about applying a rule fairly, pointing at exceptions is relevant, because what's under discussion there is not whether the rule is true but whether it's applied evenly. The line runs through the question the conversation is on: “is the rule right” or “is it applied to everyone alike”.
Claim. Don't eat on the move — you get half a day of heaviness afterwards.
Move. You finished a sandwich on the way in yesterday.
Why it is a fallacy. The speaker's behaviour doesn't affect the link between eating on the move and the symptom. It shows only that he doesn't follow his own advice either.
At work. The proposal “a regression test for every bugfix” is met with “and you merged a hotfix without one yesterday”. The author breaking the rule is a separate topic about equal exceptions for everyone; whether a regression test catches the bug coming back is untouched by that answer.
What to answer. “True, yesterday I was the one who broke the rule. Then let's close the exceptions for everyone, me included. Any objections to the rule itself?”
Straw man
straw man · straw man argument
The position is replaced with a version that's easier to refute, the replacement is refuted and the question declared closed.
The refutation lands on a wording its author never advanced. The substitution comes in several kinds: strengthening (“sometimes” becomes “always”), weakening a precise criterion into a vague one, picking the weakest representative of the position, quoting without the qualifiers about scope and time, gluing several people's positions into one. A reliable tell: victory is declared and the original wording was never once repeated back. The test is to state the position so that its author agrees with your statement of it.
Claim. I suggest we check the card spending once a week.
Move. So now we log every pack of gum and live with a calculator in hand.
Why it is a fallacy. What gets refuted is total bookkeeping, which nobody proposed. The weekly look at the statement stays undiscussed: how long it takes and what it gives never came up.
At work. “Mandatory review for changes in billing” turns, in the meeting, into “you want every line signed off and releases stopped”. From there the discussion is about stopping releases; the scope — billing only or the whole repository — is never once pinned down.
What to answer. “That's not my claim. Mine is this: … . Argue with it — or say what's unclear in my wording.”
Genetic fallacy
genetic fallacy · fallacy of origins · argumentum ad originem
A claim is accepted or rejected by where it came from, not by what it says.
The origin of an idea is evidence about the process that produced it: who had an interest, how carefully it was checked, what data was available. That affects the priority of checking, but doesn't replace the check. The fallacy appears when, after the source is named, the content is no longer examined. Data provenance stands apart: there the origin of a dataset directly determines representativeness and the right to use it, and pointing at the origin works as an argument on the merits.
Claim. Salt is better added closer to the end of cooking.
Move. That's your grandmother's folk wisdom, half her advice came out of nowhere.
Why it is a fallacy. Where the advice came from tells you how much it was tested, not whether vegetables take longer to soften in salted water. The pot answers that, not the biography of the source.
At work. “Marketing proposed this caching scheme, so technically it's nonsense.” The source predicts whose interests stand behind the proposal, but not what happens to the cache when a price changes. The same appeal to origin is legitimate for a dataset: where the data was collected from is precisely the substantive question about the sample.
What to answer. “Where the idea came from is a separate conversation. What in it doesn't work?”
Psychologist's fallacy
psychologist's fallacy
Your reading of someone else's state is passed off as the state itself, and the argument goes on against the reading.
The observer describes another person's experience from his own position — knowing the outcome, the context, holding a vocabulary the person didn't have at that moment — and attributes that description to him as a fact. In an argument the move works as an attack: the opponent is told what he really feels, means or fears, and then what was attributed to him is refuted. Only what was said stays checkable; inner motives are a hypothesis the person confirms or rejects himself, not the observer.
Claim. That gym is inconvenient for me: it's forty minutes each way.
Move. Really you're just too lazy to train, the time has nothing to do with it.
Why it is a fallacy. The trip is checked on a map; “laziness” is an attributed state the other person said nothing about. Arguing with an attributed state doesn't shorten forty minutes.
At work. In a post-mortem: “the on-call didn't escalate because he was afraid of looking incompetent”. The person running the review sees the whole picture and knows the outcome; the on-call at three in the morning had partial metrics and a runbook with no branch for this. Until the reason is confirmed by the person himself and by the timeline, it's the observer's reconstruction, not a fact of the incident — and it blocks finding the real defect in the process.
What to answer. “That's your reconstruction of my state. What I said was this: … . Let's discuss what was said.”
Circumstantial ad hominem
circumstantial ad hominem · argumentum ad hominem circumstantiae
The claim is declared false because the author's position or gain gives him a motive to say it.
A conflict of interest is grounds for a check, not a verdict of falsity. The correct form is limited to trust: testimony from an interested party can't count as independent, so it has to be re-checked. The incorrect one takes an extra step and replaces the re-check with a ready-made conclusion. The tell: after the interest is pointed out nobody checks anything, and the question is treated as settled.
Claim. We don't need a water filter: the test says the water here is fine.
Move. Sure, you just grudge the money, that's why you say it.
Why it is a fallacy. Not wanting to spend explains why that conclusion suits him, but what's in the water is determined by the test, not by the state of the budget. An interest is a reason to order your own test, not to call someone else's false.
At work. “He's pushing a managed database because he used to work for a cloud provider.” A previous employer is a reason to ask him for a TCO calculation and a self-hosted scenario, not a reason to treat his operating-cost figures as wrong.
What to answer. “I do have an interest and I'm not hiding it. So check the numbers — here are the inputs, run it yourself.”
Tone policing
tone policing · tone argument
The answer on the merits is postponed by pointing at the form, the volume or the emotion of what was said.
Delivery and content are independent properties. Asking someone to speak more calmly can be legitimate as a separate request about the norms of communication, but it doesn't answer a factual claim and doesn't change whether it's true. The fallacy appears when meeting the form becomes a condition for discussing the content: then any indignation automatically devalues what stands behind it, and the side with the calmer voice gets a free way not to answer.
Claim. That's the second time you forgot the parcel, it's been sent back.
Move. As long as you're raising your voice, I'm not discussing this.
Why it is a fallacy. The parcel went back to the sender regardless of how loud the conversation was. Tone can be discussed, but as a second topic, not instead of the first.
At work. In the incident channel an all-caps message “the prod key is in a public repository” is answered with “let's not panic”. A norm of calm communication is reasonable and belongs in the retro; the key is still valid — revoke and rotate first, talk about tone afterwards.
What to answer. “Fair, I'll say it more calmly. Repeating: … . What do we do about it right now?”
Guilt by association
guilt by association · association fallacy · damning by association
A claim or a thing is discredited through whoever else shares or uses it.
Two objects sharing one feature doesn't carry the rest of the properties across. For proximity to mean anything a transfer mechanism has to be named: a common author, a common dependency, a common manufacturing process, a common source of funding. Without a mechanism it's an association in the listener's head, not a property of the thing under discussion. The mirror version — “endorsement by association”, where a respected name is placed alongside — is wrong in exactly the same way.
Claim. This way of washing windows without streaks works.
Move. That's advice from the blog where colds are treated with onions.
Why it is a fallacy. A shared source carries no property over to the method. After washing, the window either has streaks or it doesn't, and that's visible without knowing the blog's other advice.
At work. “This library is pulled in by the outfit that leaked user data, so it's insecure.” The transfer needs a channel: a shared maintainer, a compromised supply chain, a shared vulnerable dependency. What gets checked is CVEs, the release signature and a code audit, not the list of users.
What to answer. “What exactly transfers, and through what channel? If it's a shared dependency, name it and we'll look together.”
Appeal to accomplishment
appeal to accomplishment
The right to judge is derived from a track record: achieve something first, then talk.
Accomplishments are evidence of the speaker's past results, not of the quality of this particular argument. The move is symmetric: the author's success is presented as proof he's right, the opponent's lack of success as proof he's wrong. In both directions the argument itself stays unexamined. Experience is relevant when the claim rests on personal testimony or a narrow qualification, and then what gets checked is whether the field of experience matches the question, not the scale of the biography.
Claim. This recipe has a bit too much salt for that volume.
Move. Have you ever cooked for twenty people? Open a restaurant and then we'll talk.
Why it is a fallacy. The ratio of salt to the weight of the ingredients is checked with scales and a taste. Experience of cooking for twenty makes the speaker's opinion more likely right, but doesn't remove the option of recounting the grams right now.
At work. At an architecture review: “I've taken three systems of this scale to production” instead of doing the numbers on the new sharding scheme. Experience is a reason to listen closely, not a substitute for the estimate: how many requests land on a shard, where the hot key is, what happens on a resplit.
What to answer. “You have more experience — all the easier to explain: at which step does my calculation break?”
Courtier's reply
courtier's reply
Criticism is dismissed by pointing out that the opponent hasn't studied the subject enough — without answering the criticism itself.
A demand for erudition is put in place of an answer. An objection either points at a specific defect — a contradiction, missing data, an invalid step — or it doesn't, and that's visible from the objection itself. An appeal to the unread works as a condition that can be pushed back forever: the required reading list can always be extended by one more volume. The honest version of the same move names what in the unread material removes the objection, and gives a link.
Claim. The course promises a result in a week, and what that result consists of isn't said on the page.
Move. You haven't done a single stage and haven't read the handbook, so you can't judge.
Why it is a fallacy. The remark is about exactly what's published: there's no description of the result on the page. The handbook could fix that, but then it's enough to show the relevant paragraph in it.
At work. “First read all the design docs from three years back and the scheduler code, then we'll talk about your question on timeouts.” If the answer is in the documents, a link to the section is enough. Demanding that the whole thing be read not only dodges the answer, it masks the fact that the documentation doesn't answer the question.
What to answer. “Give me a link to the section where this is covered — I'll read it and drop the question.”
Bulverism
bulverism
The falsity of the position is treated as already established, and the speaker goes straight to explaining how the opponent arrived at it.
The move has two steps and the first is skipped: instead of “I'll show the claim is false” it's “since it's false, let me explain which fear, upbringing or trauma it grew out of”. A psychological explanation can be built for any belief, true ones included, so it doesn't distinguish truth from falsity and can't in principle serve as a refutation. The term comes from an essay by C. S. Lewis. It differs from the genetic fallacy in that the origin here isn't advanced as an argument against the claim — it takes the place of an argument nobody made.
Claim. This subscription is a bad deal: over a year it costs more than buying separately.
Move. You just grew up in a family that saved on everything, hence the fear of subscriptions.
Why it is a fallacy. Even if the biography is described correctly, it explains why that conclusion appeals to him, it doesn't check the arithmetic. The yearly total adds up regardless of anyone's childhood.
At work. “You're against the orchestrator because you got burned at your last job and now you're afraid of it.” Maybe so — but the argument was stated: the cost of operating a cluster for three services. Until the numbers are gone through, a diagnosis of motives only covers up the absence of an answer.
What to answer. “Suppose my reasons are exactly those. I did give an argument all the same: … . Show me where it's wrong.”
Changing the subject
The point under dispute is swapped for another one — more convenient, louder, or impossible to object to without looking bad.
Red herring
red herring · ignoratio elenchi · отвлекающий манёвр
Instead of an answer another, more winnable topic is introduced, and the discussion drives off after it.
The reply neither supports nor refutes the original claim — it swaps the subject. There may be no lie in it at all: everything said is true, it's just about something else. A working test: after the answer the original question can be asked again word for word. If it can, it isn't closed, and the conversation is now about something else.
Claim. The internet bill has a rental charge for the router we returned, second month running.
Move. The speed went up though — the neighbours don't have that.
Why it is a fallacy. The speed and the extra line on the bill are independent facts. The question of getting the charge back is exactly where it was, but what's on the table now is the tariff.
At work. In a post-mortem the question is why the alert stayed silent for forty minutes, and the answer is a story about how quickly the rollback went afterwards. The rollback really was quick — it has nothing to do with the hole in monitoring. The same move in an estimation argument: “how long will the schema migration take” — “the code will be cleaner after it, though”. In prioritisation: “why is this task above the rest” — “a big customer is waiting for it”.
What to answer. “That's worth discussing too, I've noted it as a separate item. Back to the original: why did the alert stay silent for forty minutes?”
Loaded question
loaded question · complex question · plurium interrogationum · сложный вопрос
The question is built so that any direct answer confirms an unverified presupposition.
The disputed statement is hidden not in a premise but in the structure of the question: you're asked “why”, “when”, “how much”, while “is it true at all” hasn't been established. Both “yes” and “no” accept the presupposition equally, so whoever answers has lost before opening his mouth. The order is broken: a presupposition is to be argued for separately, not smuggled in inside an interrogative form.
Claim. We're discussing who does the dishes in the evenings.
Move. Why do you always leave everything to me?
Why it is a fallacy. “Always” and “everything” were never discussed and never checked. The answer “because I get home late” confirms them; the answer “that's not true” looks like dodging. Both options lose in advance.
At work. In code review: “Why are you ignoring our naming conventions again?” — both “again” and “ignoring” are sewn into the question, though the argument is about one method. Internal surveys have the same disease: “How much did the new release process help you?” presupposes that it helped; the neutral version is “how did the time from merge to production change”. At a retro: “What kept us from testing properly?” already asserts we didn't test.
What to answer. “I'll answer, but first let me take the question apart: which cases exactly do you count as missed, and was that ignoring or a deliberate decision?”
Appeal to emotion
appeal to emotion · argumentum ad passiones · appeal to pity · appeal to fear
The place of the missing grounds is taken by an induced feeling — fear, pity, shame or ridicule.
Emotion by itself isn't a fallacy: it reports on values and on the price of a risk, and no decisions are made without it. The fallacy appears when a feeling is slotted in for the missing link and the strength of the experience starts working as a measure of truth. The tell is simple: strip out the emotional colouring — if neither data nor a mechanism is left, there was no argument.
Claim. We agreed: leave requests go in two weeks ahead.
Move. You're seriously going to refuse? My tickets are booked, I've waited for this trip all year.
Why it is a fallacy. Booked tickets are a solid reason to make an exception this once, but they say nothing about whether the rule itself is needed. Two different things were under discussion and are being settled as one.
At work. “Don't reject the PR, he sat over it until three in the morning” — the effort belongs to the conversation about workload, not to whether the code is correct. The mirror version through fear: “if we don't buy this scanner, the next leak will bury us”; instead of probability, damage and the effectiveness of the control, a picture of catastrophe. Ridicule works the same way: “only dinosaurs write monoliths” replaces a comparison of architectures with a reputational price.
What to answer. “The situation is hard and I'll help with it separately. On the decision itself: what numbers do we have and what happens if we're wrong?”
Quoting out of context
quoting out of context · contextomy · quote mining · ошибка акцента
The fragment is kept word for word, the condition, the qualifier and the scope are dropped — and the meaning shifts to a convenient one.
Every word of the quote is genuine; the distortion is done by the cut. What disappears is modality (“possibly” becomes “is”), the condition (“if the load doubles”), a negation, the scale, the date. Functionally it's a straw man assembled from the opponent's real words, and that makes it harder to challenge: objections are met with “I quoted you verbatim”.
Claim. What was said was: “If the guests don't come, we don't have to cook a hot dish — salads will do.”
Move. You said yourself we don't have to cook.
Why it is a fallacy. The condition “if the guests don't come” was dropped. A conditional permission turned into an unconditional statement, though formally the quote is undistorted.
At work. The thread discussed: “this service can be moved into a separate repository once the contract stabilises”. A month later the ticket links to that same thread with the wording “the team agreed to the split”. Measurements are read the same way: “the effect shows in the exploratory run and disappears after the correction” becomes “the benchmark showed a speedup”. In a post-mortem: “we wrote ourselves that the risk was acceptable” without the second half, “at current traffic”.
What to answer. “Link the whole message, please — there was a condition in it, and right now it isn't met.”
Conflict inflation
conflict inflation · раздувание разногласия
A local disagreement is stretched into a total one, and instead of one disputed point the conflict at large gets discussed.
A disagreement has boundaries: the subject, the extent, the conditions. The move erases them in two ways. First: a local “I disagree with this point” is converted into “you're against the whole approach” — and from there the argument is with a position nobody held. Second: from specialists differing on details it's inferred that nothing in the field is settled at all. In both cases the conversation drives off to where there's nothing left to check.
Claim. Let's go to your parents just for Saturday this time, not the whole weekend.
Move. So you find my family hard? Then let's settle right now whether we see them at all.
Why it is a fallacy. The objection was about the length of one trip. The expanded version doesn't follow from it, but it can't be closed in one conversation — and the original question about Saturday stays unsettled.
At work. In code review a comment on one query (“there's no index here”) is turned into “you don't trust our data model, let's revisit the whole schema”: the discussion eats half a day and the index still isn't added. The second kind shows up in technology arguments: “some benchmarks say gRPC is faster, others that the difference is within noise, so it's impossible to measure at all”. Unknowability is inferred from the spread, though the disagreement is exactly what shows which measurement to set up.
What to answer. “Slow down: I'm arguing about one line, not about the schema. On everything else we don't disagree — right?”
Appeal to morality
appeal to morality · moralistic fallacy · argumentum ad moralem
Instead of how things are, what gets discussed is how they ought to be.
A moral verdict is substituted for a descriptive claim: “you mustn't do that” answers “how should one act”, but not “what happened” and not “what will happen”. It's the mirror of the naturalistic fallacy: there “ought” is derived from “is”, here “is” from “ought”. The side effect in dialogue: the opponent's objection is reclassified as a misdeed, and he has to defend himself on something other than the merits.
Claim. If we leave at six on a Friday, we'll sit in traffic for two hours.
Move. Normal people don't build their lives around traffic jams.
Why it is a fallacy. The reply judges the person who counts travel time, not the forecast. The jam won't clear because of a verdict, and the question of when to leave is left unanswered.
At work. “Good engineers don't write code without tests” instead of an answer to whether we make the deadline with tests for this module: the conversation moves from planning to who's a good engineer here. The same in a post-mortem: “the on-call was supposed to check the dashboard” is about the norm, not about why at four in the morning the dashboard didn't tell degradation apart from a normal peak. In tech-debt arguments: “you can't leave that behind you” instead of an estimate of cost and risk.
What to answer. “I'm not arguing about what's right. Right now I need the fact: what exactly happened and with what numbers.”
Thought-terminating cliché
thought-terminating cliché · semantic stop sign · мыслепрекращающее клише
A ready-made stub phrase closes the topic without answering a single question.
The phrase looks like a conclusion but holds neither a premise nor data: “that's how it happened historically”, “it's obvious”, “the business decided so”, “it's not us, it's the way things are”. It works on a social signal: pressing on after it is awkward — it looks like arguing with common knowledge. It differs from an ordinary claim in that a cliché can be neither verified nor refuted: there's no content in it that could turn out false.
Claim. Why do we renew the insurance with this agent every year when the one next door is cheaper?
Move. That's how it's done, don't get clever.
Why it is a fallacy. “That's how it's done” describes a habit, not a reason. The price difference isn't explained, but carrying on has become awkward — and that's exactly what the move does.
At work. The question “why is there a retry with a 50 ms interval here” is answered with “legacy, don't touch it” — and a year later the next person asks it again. Standard stubs: “that's an architectural decision”, “everyone does it this way”, “no time for that” in reply to “what does it cost”, “the seniors know better”. Diagnostic: if the reply fits any question in that spot equally well, it answers none of them.
What to answer. “The decision may well be right — I need the reason so I don't break it by accident. Who put it in, and because of what?”
Appeal to the stone
appeal to the stone · argumentum ad lapidem
The claim is declared absurd without a single argument brought against it.
The answer consists of one verdict: “nonsense”, “not serious”, “that'll never fly”. Not one premise is contested, no counterexample is produced, the scope isn't narrowed — the burden of proof is silently handed back to whoever was already carrying it. The name comes from Samuel Johnson kicking a stone in reply to Berkeley's argument: a demonstration in place of a refutation. The move is cheap for the responder and expensive for the author, who has to guess what exactly is being disagreed with.
Claim. The water meter seems to be lying: usage has tripled and we live the same way.
Move. Nonsense, meters don't lie.
Why it is a fallacy. That's a restatement of the opposite opinion, not an objection: neither another reason for the rise nor a way to check the readings is named.
At work. An RFC gets the comment “this is over-engineering” — with no indication of which requirement is superfluous and what's cheaper instead. At grooming a five-day estimate is met with “that's an hour of work”, without going through a single item of the breakdown. In an incident discussion: “that can't happen” instead of a request for logs. Formally the conversation is on topic, but without a single checkable statement.
What to answer. “I may well be wrong. Tell me specifically: which step is superfluous, or which assumption doesn't hold here?”
Two wrongs make a right
two wrongs make a right · two wrongs don't make a right · два зла не делают добра
Your own dubious move is excused by someone else's identical one — and theirs is what gets examined.
From “someone else did the same” it doesn't follow that the action is permissible: both facts can be true and both violations. In dialogue the move works as a diversion: the subject turns from “what do we do about this” into “who else did it”. Someone else's precedent is relevant to a different question — whether the rule is applied fairly, or in what order things get fixed — but not to whether there was a violation here.
Claim. You parked in a disabled bay.
Move. Everyone parks like that here, look, two more cars next to it.
Why it is a fallacy. Two neighbouring cars don't make the bay permitted. From a violation being repeated it follows that the problem is widespread, not that there is none.
At work. “Yes, I hardcoded the key, but in the neighbouring service it's in the config too” — a second key means a second ticket, not closing the first. Process is bypassed the same way: “the last release also went out on a Friday without review” turns “do we roll back or fix” into an argument about past releases. The reverse version shows up too: a team that honestly filed a bug against itself gets compared with the ones that kept quiet.
What to answer. “If it's the same over there, we'll file a second ticket, thanks. This one still has to be closed: roll back or fix?”
The shape of the inference
The form of the reasoning itself breaks: a premise passes for a conclusion, an effect for a cause, ignorance for proof.
Special pleading
special pleading · особое исключение · исключение для себя
The general rule is accepted, but an exception is introduced for one's own case with no independent criterion.
The rule applies to everyone except the convenient case. What breaks isn't the inference schema but the grounds: the feature that rescues the particular case is named only after it's known whom it benefits, and it doesn't follow from any criterion that would have been accepted in advance. There's one test: would this criterion have been written into the rule before it became clear whose case it rescues? If yes, it's a rule with a scope, not special pleading.
Claim. In the building the shared bin goes out on a schedule, everyone takes a turn.
Move. Yes, but I have a small child and I work from home, so let the neighbours take my turn.
Why it is a fallacy. The circumstance is named not as a criterion applying to everyone in that situation but as a reason for this one person not to follow the rule. No conditions, no time limit, no return to the rota are offered — the exception exists for exactly one person.
At work. “Every service goes through security review before release” — and immediately “ours is experimental, we don't need it”. An exception is legitimate only if the policy defines its scope in advance by data, access and audience, with a deadline, an owner and automatic expiry. The same move: “that test is flaky only for us, we'll disable it on our side”, “the code freeze isn't about our team”, “the linter is in the way here, we'll add an ignore”.
What to answer. Ask for the exception to be stated as a rule: “Write the criterion so that it fires for anyone who falls under it, and name how long it's valid”.
Circular reasoning
circular reasoning · begging the question · petitio principii · предвосхищение основания · круг в доказательстве
The conclusion is used as its own grounds — directly or through a chain of renamings.
The schema: A because B; B because A. Compressed: A because A, where the second A is restated in other words. Such an inference is formally valid — A really does follow from A — and that's exactly what makes it dangerous: it passes the check on form and doesn't deliver what an inference is built for, an independent footing. Diagnosis by graph: draw the edges “claim ← grounds”; if there's a path from the claim back to the claim, there's no independent starting point.
Claim. This cooking site is a reliable source of recipes.
Move. How do you know? — All the recipes there are correct. — And how do you know they're correct? — Well, the site is reliable.
Why it is a fallacy. The grounds are the same claim in other words. The check has to rest on something external: a comparison with a second source or your own result from the recipe, not on the statement being checked.
At work. A model quality metric: “the model is good because it agrees with the labels; the labels are good because the model reproduces them confidently”. Without an independent gold set the system confirms itself. The same circle in operations: “the alert is configured correctly because there have been no false positives; there have been none because it's configured correctly” — while the alert may not be firing at all.
What to answer. “Name a ground I can check without accepting the original claim up front”.
Affirming the consequent
affirming the consequent · утверждение следствия · converse error
From “if A then B” and an observation of B, A is inferred, though B can have other sufficient causes.
The schema: “if A then B; B; therefore A” — that is, A → B, B ⊢ A. It doesn't preserve truth: one countermodel is enough, where A is false and B true for another reason; the implication stays true, the premises are true, the conclusion false. The source of the error is reading “if” as “only if”: a sufficient condition is taken for a necessary one. The nearest valid form is modus ponens: A → B, A ⊢ B.
Claim. If it's raining, the pavement is wet.
Move. The pavement is wet, so it was raining.
Why it is a fallacy. The pavement is also wet after a street-washing truck, a burst pipe, someone hosing down the yard. A consequence is rarely unique to one cause, so observing it doesn't single a cause out of the list.
At work. “If the certificate has expired, the TLS handshake fails. The handshake is failing, so the certificate has expired.” It also fails on a cipher suite mismatch, a wrong SNI, clock drift on the host. The same in observability: “a deploy writes a marker; there's a marker, so there was a deploy”, though the marker could have been created by hand or written twice.
What to answer. “What other causes give the same symptom? Let's list them and cut them off by measurement, not by guesswork”.
Shifting the burden of proof
shifting the burden of proof · onus probandi · перенос бремени доказательства
One person advances the claim, the other is required to prove it false.
The primary burden lies with whoever advances a substantive claim. The reply “prove it isn't so” swaps a feasible task — produce one piece of evidence — for a practically impossible one: exhaust every possible case. The burden isn't glued to a person forever: once sufficient evidence is produced it moves, and the other side then has to contest the data, show an alternative, narrow the conclusion or give counter-evidence. The fallacy isn't in the burden moving, but in sending it where no claim was made.
Claim. My missing key is in this box.
Move. Don't believe me? Open it and prove it isn't there.
Why it is a fallacy. The first speaker made the claim about the contents, and checking it costs him one motion. Demanding that the other person prove absence turns an unsupported assertion into the default position: until refuted, it counts as true.
At work. “This library is insecure, prove otherwise”, “my patch doesn't break anything, go find where it does”. The engineering order is the reverse: a change is justified by the author of the change — with a test, a benchmark, a rollback plan. In safety and security there's a legitimate asymmetry: harm not being proven doesn't oblige you to do nothing, and the decision is made on the cost of type I and type II errors — but precaution doesn't make the threat proven.
What to answer. “The claim is yours — show the evidence. Once it appears, I'll answer on the merits”.
Affirming a disjunct
affirming a disjunct · утверждение дизъюнкта · ложно исключающее или
From “A or B” and the affirmation of A, B is inferred false, though the “or” may be inclusive.
The schema: “A or B; A; therefore not B” — that is, A ∨ B, A ⊢ ¬B. For an inclusive ∨ the form doesn't preserve truth: A and B can be true together, the premises stay true and the conclusion is false. It's valid only for an explicitly exclusive “exactly one of the two”: A ⊕ B, A ⊢ ¬B. For an ordinary “or” the valid form is the disjunctive syllogism: A ∨ B, ¬B ⊢ A.
Claim. On Saturday either Anya or Boris will drop by.
Move. Anya's already written that she's coming, so no Boris, we're not putting out a third chair.
Why it is a fallacy. The sentence didn't promise that exactly one would come. Until “one of the two” is stated, Anya coming tells you nothing about Boris.
At work. “The cause of the incident is either a configuration error or a code error. The config turned out broken, so the code is clean” — and the investigation is closed, while the second cause stays in production until next time. The same defect in code: `const allowed = isEmployee || hasBetaAccess;` and below `if (isEmployee) assert(!hasBetaAccess);` — the assert blows up on an employee who also has beta access.
What to answer. “Is this ‘or’ exclusive? Who wrote that down, and where? Until it's written down, we check both options”.
Appeal to ignorance
appeal to ignorance · argumentum ad ignorantiam · аргумент от незнания
Absence of proof is passed off as proof of absence — or the other way round.
Two mirror schemas: “it isn't proven that P, therefore not P” and “it isn't proven that not P, therefore P”. Both are invalid: ignorance is a state of the knower, not a property of the world. Absence of evidence becomes evidence of absence only when the conditions are met: the search used a suitable method, the method would have found the object with high probability, the search area was covered, the result is reproducible. Then the conclusion is stated together with those boundaries and isn't extended past them.
Claim. We've got mice in this flat.
Move. Nobody has ever seen a mouse, so there are no mice.
Why it is a fallacy. Nobody looked either: no traps were set, nobody looked behind the cooker or under the sink. “We haven't observed them” and “they aren't there” are different claims; the second requires a search that would have found the mice if they were there.
At work. “There's nothing in the logs, so there was no error.” There may be no logging on that path, the level may be set to WARN, the record may have been lost to rotation or sampling. The correct wording after a check: “after a full scan of the image with a known signature set there's no evidence of these specific CVEs” — a bounded conclusion, not “the image is secure”.
What to answer. “What exactly was searched for, by what method — and would that method have found it if it were there?”
Denying the antecedent
denying the antecedent · отрицание основания · inverse error
From “if A then B” and “not A”, “not B” is inferred, taking a sufficient condition for a necessary one.
The schema: “if A then B; not A; therefore not B” — that is, A → B, ¬A ⊢ ¬B. A countermodel is built instantly: let B be true for another reason while A is false — both premises are true, the conclusion false. The implication forbids exactly one combination (A true, B false) and says nothing about the case where A is false. The nearest valid form is modus tollens: A → B, ¬B ⊢ ¬A.
Claim. If an item is fragile, a special sticker goes on the box.
Move. There's no sticker, so it isn't fragile, it can go at the bottom.
Why it is a fallacy. The sticker could have been forgotten, it could have peeled off, the batch could have been packed under the old instructions. The rule guaranteed a sticker on the fragile, not sturdiness for everything without a sticker.
At work. “If the request is from an administrator, the report is available. The request isn't from an administrator, so there's no access” — though an auditor or the resource owner may hold the right. The same in diagnosis: “there was no release, so the degradation isn't from changes”; config, feature flags, data and dependencies all change without a release.
What to answer. “Is this condition sufficient or necessary? Name the other paths to the same result”.
Proof by assertion (repetition)
proof by assertion · proof by repetition · argumentum ad nauseam · доказательство повторением
The claim is repeated unchanged and more insistently instead of being given grounds.
Repetition adds not a single new fact to the claim: after the tenth time the set of evidence is exactly what it was after the first. The move runs on psychology — a familiar wording feels more plausible — not on logic. It's a close relative of the circle: there the claim props itself up by renaming, here it takes the place of the grounds through frequency and volume.
Claim. Going over the bridge to the cottage is faster than going round.
Move. Why? — Because it's faster. I've told you twenty times: just faster, that's all.
Why it is a fallacy. At the fifth repetition there's as much data about travel time as at the first: none. The question is settled by one measurement on the two routes, not by insistence.
At work. “This library doesn't suit us” in a third email running without a single number; “that's how we do it here” instead of an ADR; “microservices are faster” at every design review. Repetition is admissible only as a reference to an argument already made (“see the measurement in the thread above”) — otherwise it's filling the channel, after which the decision is made not by whoever is right but by whoever writes longest.
What to answer. “I heard the claim and I remember it. Now the grounds: data, a measurement or a link”.
Irrelevant conclusion (ignoratio elenchi)
ignoratio elenchi · irrelevant conclusion · missing the point · мнимое опровержение · незнание опровержения
What gets refuted isn't the claim that was advanced, and the original is declared refuted.
A real refutation requires a contradiction on the same subject, on the same predicate, in the same respect, at the same time and in the same modality — and without including the original claim among the grounds. A false refutation proves something adjacent: a weaker statement, a different topic, a special case — and transfers the effect of victory onto the original claim. The schema can be impeccable: the failure isn't in the form of the inference but in the addressing — the conclusion is true and doesn't touch the dispute.
Claim. The kettle leaks, it's time to fix it.
Move. Come on, it's a great kettle, we bought it five years ago and it still boils water in three minutes.
Why it is a fallacy. Nobody disputed that the kettle boils and has lasted five years. What had to be refuted was “it leaks”, and what was refuted is “it's bad” — a claim nobody advanced.
At work. “This stream needs idempotency” — “Kafka is a complicated technology”: the answer can be true and still not touch the requirement. The same move in a post-mortem: “the alert fired forty minutes after the event” is answered with “we fixed it in two hours though, the MTTR is good”. The metric is real, the claim is a different one — and the post-mortem is left with an unexamined hole in detection.
What to answer. “Let's write the original claim down verbatim. What in it does your argument deny?”
The “I am entitled to my opinion” fallacy
I am entitled to my opinion · entitled to my opinion · право на мнение вместо основания · subjectivist fallacy
The right to state an opinion is passed off as grounds for holding the opinion true.
Two different things get mixed up: the freedom to hold and state a position — which nobody contests — and whether the position is justified, which is exactly what's under discussion. The phrase “that's my opinion” adds not a single piece of evidence and closes the conversation at the same time: an argument about facts is converted into an argument about rights, where any objection looks like an attack on the person. In essence it's a form of refusing the burden of proof — “my opinion” said instead of “here's why”.
Claim. This milk is pasteurised, there's no need to boil it before making porridge.
Move. I don't know, I think any milk should be boiled. I'm entitled to my opinion.
Why it is a fallacy. Nobody was contesting the right; the question under discussion was factual — what pasteurisation actually does. Appealing to the right doesn't answer it and strips the conversation of its subject: there's nothing left to discuss, though the question is settled by one line on the carton.
At work. In code review: “I think the layers should be split” — “and I think they shouldn't, it's a matter of taste”. Some decisions really are matters of taste, and those get closed with a linter or a coin toss. But “that's how it feels to me” instead of an argument about cohesion, testability or the cost of a future change isn't a position, it's a refusal to justify one. “That's my architectural vision” in reply to a benchmark sounds exactly the same.
What to answer. “The right to an opinion is beyond dispute, I'm not asking about the right. What does the opinion rest on?”
Vacuous truth
vacuous truth · пустая истинность · истинность на пустом множестве
A statement is true only because no case capable of refuting it exists — and it sounds like substantive confirmation.
In classical logic the implication A → B is always true when A is false; correspondingly ∀x(Sx → Px) is true if no x satisfies Sx. “Every unicorn in my stairwell is polite” is true. There's no formal error here: the rule is correct, and giving it up breaks more than it fixes. The trap is in the interpretation: a vacuous truth is read as empirical confirmation and given an existential meaning the formula doesn't carry — ∃x(Sx ∧ Px) doesn't follow from ∀x(Sx → Px). The tell of vacuity: with an empty S the opposite rule ∀x(Sx → ¬Px) is true as well, and two mutually exclusive confirmations at once are never substantive.
Claim. I throw out any expired food the same day.
Move. I checked the fridge — nothing expired. So the rule works and is followed perfectly.
Why it is a fallacy. The rule was never applied: not one case it covers turned up. “Never broken” and “confirmed” are different things. On an empty set “I eat everything expired” is equally true.
At work. A test whose filter screened out every input record passes green: “the invariant holds for all records” is true on an empty sample. An alert saying “no SLA violations in twenty-four hours” behaves the same way if the metric stopped arriving, and so does a policy saying “all requests from role X are logged” if role X is granted to nobody. The cure is a cardinality check: assert on the number of objects that fell under the condition first, then assert on the property.
What to answer. “How many cases actually fell under the condition? If it's zero, the statement is true and tells you nothing”.
The fallacy fallacy
fallacy fallacy · argument from fallacy · argumentum ad logicam · ошибка обращения к ошибке
From the argument for a claim being bad it's inferred that the claim itself is false.
The schema: “argument A supports C; an error is found in A; therefore not C”. It doesn't preserve truth: the bridge is destroyed, not the bank — a true statement can have appalling grounds, and the error found returns the claim to the status “not proven”, not “refuted”. The burden thereby doesn't disappear, it moves onto whoever now asserts ¬C. For someone who has learned the catalogue this is the most dangerous position: the list of names turns into a weapon — instead of checking the claim a hunt for labels begins, every name recognised feels like a victory, and the conversation about how things are is replaced by a conversation about how wrongly the opponent speaks. The catalogue was built as an instrument of self-checking; in someone else's hands it more often works as a way not to answer on the merits.
Claim. On a slope like that you put the car on the handbrake.
Move. You said “everyone does it” — that's an appeal to the majority, a classic fallacy. So no handbrake needed.
Why it is a fallacy. The argument really was weak, but the slope hasn't gone anywhere. The correct outcome is “these grounds won't do, give me others”, not “the claim is false”; where the dismantled argument stood there's no refutation, just a blank.
At work. At a design review: “your latency argument is post hoc, you confused correlation with cause, so the index isn't needed”. The error in the reasoning is real, the need for the index doesn't disappear because of it — it's simply not proven by that argument, and it's checked with a query plan. The same move in a post-mortem: call someone's hypothesis confirmation bias and close it on that, without checking the data; that's how correct hypotheses that were badly stated get lost.
What to answer. “Agreed, that argument doesn't work. The claim didn't become false because of it — does it have other grounds?”
Generalisation and boundaries
An illegitimate jump between levels: from the particular to the general, from a part to the whole, from a continuum to two options.
Hasty generalisation
hasty generalisation · поспешная индукция · generalisation from a small sample
A conclusion about a whole class is drawn from a few cases that simply happened to be at hand.
Induction is legitimate, but its strength depends on the size of the sample, the way it was selected and the spread inside the class. The fallacy appears when the number of observations is never stated, the cases were collected by availability, and the conclusion is formulated with no quantifier and no qualification. The distinction to draw is not “few examples” against “many”, but “the sample reflects the class” against “the sample reflects what I happened to notice”. The legitimate version is a generalisation with an explicit base: how many observations, where they came from, and how uncertain the conclusion is.
Claim. The courier service is bad.
Move. They brought my order late twice, so they are always late.
Why it is a fallacy. Two observations by one person do not give you the share of late deliveries, and memory holds on to the failures more readily than to a dozen deliveries on time.
At work. Two crashes on one instance turn into “the library leaks”; three messages in a chat into “users do not need this feature”; a single benchmark run on a laptop into “the new version is faster”. The cure is the number of observations and the spread stated next to the conclusion: p95 over 40,000 requests in a week on prod, not “it opens fast for me”.
What to answer. Ask how many cases there were and how they came into view. Ask for the conclusion to be restated with a quantifier: in what percentage of cases, and on what base.
Slippery slope
slippery slope · скользкий склон · аргумент домино
The inevitability of the last step is derived from the first, without a single intermediate transition being shown.
The fallacy is not that a chain of consequences was named, but that its links are missing: the mechanism of each transition, the probability of each step, the timescale, and whatever could stop the chain. A legitimate version exists and is common: if the mechanism is named and confirmed — positive feedback, accumulating precedent, path dependence, the absence of a stopping rule — the argument becomes an ordinary risk assessment. Then it can be disputed on the numbers instead of waved away with a label.
Claim. A child asks to go to bed half an hour later on Friday.
Move. Allow it once and he will stop going to bed on time at all.
Why it is a fallacy. Between “later on Friday” and “never on time” every step is missing, and nothing is said about why the rule “weeknights as usual” would suddenly stop working.
At work. “Grant one exception to code review and control falls apart”; “turn on one feature flag with no expiry and the product becomes a pile of branches”. The second is sometimes true: flags with no owner and no expiry date really do accumulate, and the counter shows it. The difference is that an honest argument shows the counter and the absence of a cleanup procedure, not only the frightening finale.
What to answer. Ask for the links to be written out one by one, with a mechanism and a limiter named for each. Ask what exactly prevents stopping at the second step.
False dilemma
false dilemma · ложная дилемма · чёрно-белое мышление · either/or fallacy
The space of options is narrowed to two, although a third is available and simply was not named.
A split on “P or not-P” is exhaustive by construction; a list of “A or B”, where A and B are two substantive decisions, almost never is. The fallacy arises when hybrids, gradations, deferring the decision and the option “change nothing for now” drop out of the list. The legitimate version: the options really do exhaust the space when a binary predicate applies, or a physical or contractual constraint, or a resource that has already been spent. Then the dilemma is real, and the answer to it is a choice, not a search for a third way.
Claim. We need to decide what to do with the old car.
Move. Either we sell it now or we drive it for another five years.
Why it is a fallacy. There is repairing it and selling it in a year, trading it in with a cash difference, driving it until the first major breakdown. The two-item list was chosen, not derived from the constraints.
At work. “Either microservices or we do not scale”, “either we rewrite from scratch or we live with this code”, “either 100% coverage or there are no tests”. A strangler migration, extracting a single module, or covering the critical path are almost always available. The check is cheap: name the third option out loud and watch whether it is rejected with an argument or with silence.
What to answer. Name a third option and ask for an explanation of what exactly rules it out. No explanation — the list was a rhetorical device.
Fallacy of composition
fallacy of composition · перенос свойства частей на целое
A property of every part is ascribed to the whole, although the assembly has a behaviour of its own.
The step “part → whole” is legitimate for additive properties, or where a law of composition has been demonstrated: the mass of the whole equals the sum of the masses of the parts. For everything else the assembly acquires an operator of its own — a bottleneck, an interaction, competition for a shared resource, ordering. The fallacy is that the operator is silently taken to be the identity. The honest move is to name how exactly the property adds up, and to check that at the boundaries.
Claim. The guests praised every dish individually.
Move. So the dinner as a whole was a success.
Why it is a fallacy. The combination may not work: three similar flavours in a row, everything gone cold by the time it was all served, heavy after heavy. The property “tasty” does not add up automatically.
At work. “Every service holds 1000 RPS, so the chain holds 1000 RPS”: it holds as much as its narrowest link, and less under fan-out and correlated spikes. “Every module is 90% covered, so the behaviour of the system is 90% covered”: module coverage says nothing about the paths that cross boundaries. The rule: name the composition operator — the latency of a sequential chain adds up, availability multiplies, memory competes.
What to answer. Ask by what law the property carries over to the whole, and give a case where the whole behaves differently from its parts.
Fallacy of division
fallacy of division · перенос свойства целого на части
A property of the whole is ascribed to each of its parts.
The step inverse to composition: from “the system has X” one derives “every component has X”. It is legitimate when the property distributes by construction — all the elements carry the feature the set was assembled on. For aggregates — averages, sums, reliability figures — it does not work: an aggregate rests on compensation, redundancy and load distribution. A distinct variety is the ecological fallacy, where group statistics are carried over to an individual member of the group.
Claim. The team closes tasks quickly.
Move. So everyone on the team works quickly.
Why it is a fallacy. The team's speed is a result of how the work is distributed and of mutual help: the hard items go to whoever has met them before. An individual member's pace cannot be derived from the aggregate.
At work. “The system is 99.9% available, so every component is 99.9% available”: components have different SLOs, different redundancy and different positions on the critical path, and some of them can be down with no consequences. “Average latency is 50 ms, so requests answer in 50 ms”: the p99 tail has a life of its own. “The company is profitable, so every product is profitable”: a loss-making product is subsidised by the rest.
What to answer. Ask whether the property distributes by construction or whether this is an aggregate. Ask for a breakdown by component and for the tail of the distribution, not the mean.
No true Scotsman
no true Scotsman · appeal to purity · апелляция к чистоте
The counterexample is not refuted but retroactively removed from the class by the word “true”.
The generalisation “all A are B” meets an A that is not B. Instead of weakening the generalisation, the speaker changes the definition of A so that the inconvenient case falls outside it. There is a single diagnostic question: was the criterion set before the counterexample and independently of it, or added afterwards. A legitimate version exists: a definition really can exclude an object, provided it was fixed in advance and is applied to one's own examples and other people's alike.
Claim. A true hiker never takes a wheeled suitcase.
Move. — Marina spent three weeks in the mountains with a suitcase. — Then she is not a true hiker.
Why it is a fallacy. The thesis has been made irrefutable: any counterexample now automatically drops out of the class, and the claim has stopped saying anything about the world.
At work. “Real microservices do not turn into a distributed monolith” — and a system that has turned into one is declared not to be real microservices. “Real Agile does not require estimates” — as soon as a team that estimates works well, it is declared not Agile. The move makes an architectural style impossible to score: not a single possible negative outcome is left for it.
What to answer. Ask whether the criterion was written down before the counterexample turned up. Ask for an observable outcome to be named in advance that would count as a refutation.
Middle ground fallacy
middle ground · argument to moderation · argumentum ad temperantiam · золотая середина
From the fact that two positions are extremes it is concluded that the truth lies exactly between them.
The midpoint between two claims is a fact about where the claims sit, not about the world. The intermediate position can be false while one of the extremes is true. The move is especially visible when the extremes are chosen by the disputants themselves: the “truth” can be moved simply by taking up a more radical pole. The legitimate version: in questions of allocating a resource, of priorities and of negotiation, compromise is a normal way to decide; and in a question of measurement an intermediate estimate is correct if it comes from the data rather than from symmetry between opinions.
Claim. How much salt to put in the soup.
Move. — A spoonful. — Three. — Two, then: the truth is always in the middle.
Why it is a fallacy. The right amount is set by the size of the pot and by taste, not by the average of two opinions. Had the second person said “ten”, the “truth” would have slid up to five.
At work. “One person estimated the migration at a month, another at a year, so it is six months”. A deadline comes from decomposition and from data on comparable work, not from the midpoint between two estimates. Same with latency, instance size and log retention: the midpoint between two numbers is not a measurement. Splitting a CPU quota between teams, on the other hand, is a legitimate compromise, and there the middle is appropriate as a decision, not as a fact.
What to answer. Ask what the answer is measured with. A factual question — ask for the data; an allocation question — call the compromise a compromise, not the truth.
Continuum fallacy
continuum fallacy · sorites · парадокс кучи · line-drawing fallacy
From the absence of a sharp boundary between states it is concluded that there is no difference at all.
There is no point of discontinuity between “cold” and “hot”, but a fuzzy boundary destroys not the difference but the claim to a single natural threshold. The practical answer is an operational threshold, honestly marked as chosen rather than discovered, plus an interval of uncertainty around it. The inverse form of the fallacy is just as common: an artificial threshold is taken for a natural discontinuity, and people behave as if the two sides of it were different worlds.
Claim. One hair does not make a person bald.
Move. So there are no bald people at all — the boundary does not fall anywhere, after all.
Why it is a fallacy. What follows from the continuity of the transition is that there are borderline cases, not that the extreme cases are indistinguishable.
At work. “Nobody can name the request after which the overload began, so there is no overload”: what works here is a threshold, an interval, and a check of how sensitive the decision is to the threshold. The other side: “79 ms is fast, 80 ms is slow”, even though the 80 ms SLO was made up in a meeting. The threshold is a management decision: you revise it, you do not defend it as a law of nature.
What to answer. Agree that the boundary is fuzzy, and still ask for the two extreme cases to be told apart. Then ask where the threshold is and who chose it.
False analogy
false analogy · weak analogy · faulty comparison
From similarity in one feature, similarity in another is inferred, although there is no link between the two features.
Analogy is a legitimate and sometimes the only available instrument: it carries a conclusion from a studied case to an unstudied one. The strength of the transfer depends on whether the shared feature is relevant to the conclusion and whether there are differences working against it. The fallacy appears when an inessential feature is transferred, the differences are not named, and the similarity rests on an image. The check is simple: name the feature the transfer runs on, and explain why it is the one responsible for the property in question.
Claim. A flat renovation should be run to a plan.
Move. A flat is like an organism, and an organism is treated as a whole; so the renovation has to be done in all the rooms at once.
Why it is a fallacy. What a flat and an organism share is a metaphorical wholeness, not the thing the order of works depends on. Rooms, unlike organs, have no shared bloodstream, and you can live in half a flat.
At work. “A database is like a file system, so a backup by copying files will do”: they share a lot, but a DBMS has open transactions and a write ordering. “They have a similar service and it worked for them, so it will work for us”: similarity in language and domain does not carry the conclusion across if the load profile and the cost of an error differ. Working an analogy through is always a finite job: write out the similarities, the differences, and which of them the conclusion is attached to.
What to answer. Ask which feature exactly the transfer runs on, and name the difference that breaks the conclusion.
False equivalence
false equivalence · false balance · ложный баланс
Two cases are declared identical on a shared feature, ignoring the difference in scale, frequency and consequences.
A shared property can always be found: being five minutes late and wrecking a trip are both “breaking an agreement”. The fallacy is that the shared name replaces measurement: scale, frequency, reversibility, cost. A related form is false balance, where two positions are given equal room only because there are two of them, regardless of what backs each one. A legitimate version of the comparison exists: name the axis on which the cases really are equal, and admit that on the other axes they diverge.
Claim. Both neighbours are loud.
Move. Drilling a wall once a year in the daytime is the same thing as playing music every night. They both make noise, after all.
Why it is a fallacy. The shared category “noise” is there, but the frequency, the time of day and the reversibility differ by orders of magnitude. The equality rests on the name, not on a measurement.
At work. “Both teams broke the process”: one shipped a hotfix without review during an incident, the other has been merging without tests for six months. “Both options have risks” — true and useless until the probability and the damage are named. In a post-mortem this is the most frequent substitution: one word, “bug”, for a typo in a dashboard and for data loss.
What to answer. Agree with the shared feature and immediately ask about the axis: by how much, how often, with what consequences, and is it reversible.
Nirvana fallacy
nirvana fallacy · perfect solution fallacy · сравнение с идеалом
A working solution is rejected for not being perfect, without being compared to the alternative actually available.
The comparison should not be against imagined perfection but against what happens without the measure, and against the best available option. An honest form of the comparison contains three quantities: the expected damage without the measure, the expected damage with it, and the cost of the measure itself together with its side effects. The inverse fallacy deserves to be named in the same voice: accepting any improvement without comparing it to the best available alternative is the same substitution, only with the sign flipped.
Claim. Whether to fit a second lock on the door.
Move. Any lock can be picked, so there is no point.
Why it is a fallacy. The question is not about a guarantee but about how the probability and the costs change compared with one lock, and what that costs.
At work. “A canary does not catch every incident, so it is useless”, “a linter does not find logic errors, what is it for”, “a second factor will not save us from a targeted attack, so we will not roll it out”. Every measure removes its own class of failures, and it is judged by the share of incidents removed and by its price, not by the existence of the ones left. The same move in reverse: “any monitoring is better than none” — until you compare it with the one that costs the same and covers twice as much.
What to answer. Ask what exactly we are comparing against: ask for the alternative to be named and for the damage in both scenarios to be estimated, along with the cost of the measure.
Causes and data
A wrong conclusion drawn from observations: about a cause, about a probability, about a sample. This is the family that incident reviews break on.
Anecdotal evidence
anecdotal evidence · argument from anecdote · «у меня сработало»
One memorable case is put in place of data on how often it actually happens.
Personal experience is a sample of size one, and it was not selected at random but because it stuck in the memory. Competing explanations are almost always at hand: coincidence; regression to the mean (help is sought at the worst point, and after the worst point things usually get better); survivorship bias — the cases where it did not work simply never get told. Experience is good as a source of a hypothesis and as a description of a mechanism, but not as an estimate of frequency: it has no denominator. More on small samples and selection in chapter 09.
Claim. A neighbour took a vitamin at the first sign of a cold and was better in three days.
Move. So the vitamin cures colds.
Why it is a fallacy. A cold clears up in a few days without any treatment, and the vitamin gets taken at the peak of the symptoms. The “took it and was ill for a week” cases never come up in conversation: there is no comparison group and no count of attempts.
At work. “At my last job Kafka lost messages on us, so we are not taking it” — one incident three years old, on someone else's version and someone else's configuration, against the experience of thousands of installations. Same in support: three loud tickets in one morning look like an epidemic until you work out the share — 3 reports per 40,000 sessions, that is, inside the normal background. Before you change the architecture or roll back a feature on the strength of a story, ask for the denominator, the version, the configuration and the period; one vivid case sets a hypothesis, but the decision is made on the rate.
What to answer. How many such cases were there in total, and how many of them ended differently? Do we know the rate — or only the one outcome that stuck in the memory?
Texas sharpshooter fallacy
texas sharpshooter fallacy · мишень вокруг попадания · post hoc субгруппа
The target is painted after the shot: the hypothesis is fitted to a random cluster already spotted in the data.
Any sufficiently large data set contains clumps — that is a property of randomness, not a signal. The fallacy arises when the segment, the window or the metric is chosen after looking at the result, and the find is presented as a confirmed prediction. There is only one competing explanation here, and it is settled by arithmetic: multiple comparisons. Twenty metrics across five segments in four windows is hundreds of tests, and at a level of 0.05 dozens of “significant” ones will turn up on their own. A hypothesis born out of the data can only be tested on new data.
Claim. Four children were born in the house on the corner last year, and all of them were boys.
Move. Something in that house affects the sex of the child: the water, the layout, the location.
Why it is a fallacy. The house was picked after the coincidence had been noticed. Four boys in a row is roughly one chance in sixteen; in a city with thousands of houses such runs are bound to occur by the dozen. The target was painted around the hit, not the other way round.
At work. The A/B test showed no effect on the full sample, so the analyst slices the data by segment and finds +8% conversion for Android in Germany in the second week. There were about a hundred tests — five false positives are expected even when the effect is exactly zero. The right move: write the find down as a hypothesis and check it with a pre-registered test on new traffic, rather than shipping a release off a subgroup. Same with alerts and dashboards: if you watch 300 charts, several metrics “degrade” every day. Separate exploratory and confirmatory analysis explicitly, down to separate documents.
What to answer. Were this segment, this window and this metric chosen before we looked at the data? How many slices were tested in total, and what did the rest show?
Cum hoc ergo propter hoc
cum hoc ergo propter hoc · корреляция не равна причинности
From the fact that two quantities move together it is concluded that one causes the other.
Moving together is compatible with at least six structures: X causes Y; the reverse direction, Y causes X; a common cause Z acts on both X and Y; the association is manufactured by selection — by how the data got into the sample; feedback; and finally plain coincidence. Correlation narrows the list of hypotheses but does not pick from it. To speak of a cause you need a mechanism, a temporal order and a comparison group — the causal protocol of chapter 09.
Claim. The more ice cream a city sells in a day, the more lifeguard callouts there are at the beach.
Move. Ice cream makes people careless in the water.
Why it is a fallacy. The common cause is the heat: it drives people to the kiosk and into the water at the same time. Neither quantity affects the other; take the ice cream away and the number of callouts will not change.
At work. The dashboard shows it: services with frequent deploys have more incidents. The conclusion “frequent releases break prod” turns the picture upside down. The common cause is criticality and activity: loaded, actively developed services get more changes, more traffic and better observability, which simply means more recorded incidents. The arrow may also point the other way: after an incident you fix and ship more often. Before you introduce a release window, look at change failure rate per deploy rather than incident count per service, and compare against services of comparable criticality.
What to answer. What could have acted on both the supposed cause and the outcome at once? And could the arrow be pointing the other way round?
Sunk cost fallacy
sunk cost fallacy · escalation of commitment · «столько уже вложено»
Past unrecoverable investment is offered as a reason to continue, although the decision depends only on the future.
Money, time and reputation already spent will not come back under any choice — which means they are identical in both branches and cannot tell them apart. What has to be compared is future benefit, future cost and the best alternative. The past is relevant exactly to the extent that it created an asset, an obligation, accumulated knowledge or an exit cost. A related mechanism is escalation of commitment: after a public decision it is easier to put in more than to admit a mistake; see chapter 10.
Claim. The cinema tickets are bought, but by the tenth minute it is clear the film is dull.
Move. We have to sit it out to the end, otherwise the money is wasted.
Why it is a fallacy. The money is spent in both options. The choice is between “an hour and a half of boredom” and “a free evening” — the past payment does not enter that comparison at all.
At work. An internal platform has been written for two years by six engineers, and the service migration has not moved. The argument “we have put in so much, we cannot drop it now” replaces the real question: if the platform did not exist today, would we start it at the current price of an off-the-shelf solution and the current requirements? The same conversation applies to a legacy rewrite, to killing an experiment with two months of collected data, and to the home-grown scheduler. The cure is not willpower but process: stop conditions and budget are fixed before the start, a kill review sits in the calendar, and the decision to continue is not made by the author of the hypothesis.
What to answer. If we ran into this opportunity today, having put nothing in yet — would we start? Which costs are still ahead of us rather than behind?
Post hoc ergo propter hoc
post hoc ergo propter hoc · после этого — значит из-за этого
From the fact that B happened after A it is concluded that A caused B.
Temporal order is necessary for a cause but not sufficient. Competing explanations: coincidence; a common cause that set off both events; a process that started earlier and surfaced with a delay; regression to the mean — the intervention is usually made at the peak of the problem, and after the peak things get better by themselves; and finally, what changed was the measurement, not the thing measured. The closer the events are in time, the more convincing the illusion and the more a comparison group is needed.
Claim. The child coughed for a week; yesterday he was given a syrup a neighbour suggested — today the cough is nearly gone.
Move. The syrup cured the cough.
Why it is a fallacy. The syrup was given on the seventh day, when the illness was already on the way out. Medicine is almost always started at the worst point, and after the worst point the outcome improves on average regardless of treatment — that is regression to the mean, not an effect of the syrup.
At work. A release went out at 14:05, at 14:12 p99 tripled, it was rolled back — things got better, incident closed with the cause “the release”. Check: did the chart start climbing before 14:05? Did a nightly batch start in that window, did a dependency degrade, did a config change? Did the rollback coincide with the end of the peak hour? A rollback changes the entire state of the system at once, so “it got better after the rollback” is exactly the same post hoc as the original conclusion. A cause counts as confirmed when there is a mechanism and a reproduction (the same query on a copy of the data, say), not just a coincidence of timestamps.
What to answer. What else changed in the same window? Had the metric already started climbing before the event — and is there a comparable group where the event did not happen?
Ecological fallacy
ecological fallacy · ecological inference fallacy · перенос среднего на индивида
A property of a group, computed as an average, is carried over to each of its members.
Group-level statistics and individual-level statistics are different quantities; the association between them can differ in strength and even in sign. The competing explanation for an aggregate association usually lies not in people's behaviour but in the composition of the groups and the weights of the subgroups; the extreme case is Simpson's paradox, where the trend inside every group is the opposite of the trend in the union (chapter 09). The mirror-image fallacy is called atomistic: an individual-level regularity is carried over to groups, ignoring coordination, specialisation and the division of work.
Claim. The average income in district A is higher than in district B.
Move. So the person you know from district A earns more than the one from district B.
Why it is a fallacy. The average says nothing about one particular pair of people: A may hold a few very wealthy households and many modest ones. The spread inside the districts is larger than the difference between their averages.
At work. Teams with high test coverage take prod down less often — from which it is concluded that every engineer who raises coverage on their own module will cut their own incidents. The unit of analysis has been swapped: what works at the team level is code review, CI, on-call and which services the team was handed, not coverage on its own. The same slip in a performance review (“the team has high throughput” does not make every individual's throughput high) and in SLOs: 99.9% availability for the whole service does not mean 99.9% for every customer — a single tenant can absorb the entire error budget. Declare the unit of analysis — request, session, user, team — before you count, and do not mix levels inside one conclusion.
What to answer. What is the unit of analysis here — the group or the individual? Is the spread inside the groups no larger than the difference between them?
Historian's fallacy
historian's fallacy · суд задним числом · hindsight в оценке решений
A past decision is judged with knowledge the person deciding did not have at the time.
What gets swapped is the information state: the outcome is already known, and the signals that led to it look singled out in hindsight, while the dozens of equally weighty signals that were drowning in the noise back then are invisible. The competing explanation is not “the person did not think it through” but “at that moment the information was indistinguishable from the background”. The cognitive lining of the fallacy is hindsight bias, the “I knew it all along” effect (chapter 10). An honest assessment asks what was available at the moment of the decision; the historian's fallacy asks why nobody guessed what we know now.
Claim. Last summer a family picked a hotel from the reviews and the photos; on arrival there was a building site under the windows.
Move. How could you not check — you should simply have picked a different hotel.
Why it is a fallacy. The building site started after the reviews were published and was not visible in any source available at the time. What is being judged is not the decision but its outcome: with that information the choice was sound.
At work. In the post-mortem someone says: “but the alert fired at 3:40, why did the on-call not react”. At 3:40 that alert was one of seventeen, fourteen of which are noise every night; it became the salient one only after we learned the answer. The difference from an honest walkthrough is fundamental: a post-mortem reconstructs what information was available and what made it hard to see, and then adds a signal, a runbook or automation — that is, it changes the system; the historian's fallacy looks for who failed to guess — and teaches people to put fewer details into their reports. Hence the blameless review rule, a timeline built strictly from the data available at the time, and a decision log with the reasoning written down before the result.
What to answer. What did the person know at that minute — and what did it look like among the rest of the noise? Are we judging the decision, or the outcome we already know?
Incomplete comparison
incomplete comparison · сравнение без базы · «на 30% лучше»
A comparative claim is presented without the second term of the comparison, without a baseline and without the conditions of measurement.
“Faster”, “cheaper”, “40% more efficient” are two-place relations. Until it is said than what, under which conditions and by which metric, they cannot be checked, and the listener fills in whichever version suits the speaker best. The competing explanations hide precisely in what is left unsaid: the baseline was chosen for convenience, the denominator was never named, a relative effect was shown instead of an absolute one, the window was picked to fit. Related moves are the denominator fallacy and the substitution of relative risk for absolute risk (chapter 09).
Claim. On a yoghurt pot: “New formula — 50% less sugar”.
Move. So the product is low in sugar and suits people watching what they eat.
Why it is a fallacy. It is not said less than what: than the previous version of the same brand, which had twice the usual amount of sugar? Half of a lot is still a lot. Without the starting level and the absolute grams per serving the comparison cannot be checked.
At work. “The new service is three times faster” — faster than what: than the old version on a cold cache, on a different machine, under a different load profile? Which metric — the mean or p99, on what share of requests, how long did the run last? A classic of the post-release report: “50% more errors” with no request count — with traffic doubled the error rate has actually gone down. Demand five things: the numerator, the denominator, the comparison baseline, the window, and absolute values with their spread. In benchmarks add the configuration of both sides — otherwise what is being compared is not the systems but the effort of whoever tuned them.
What to answer. Faster, cheaper, better — than what exactly, by which metric and under which conditions? What are the absolute numbers here, and the denominator?
Gambler's fallacy
gambler's fallacy · ошибка Монте-Карло · «должно выпасть»
An independent random process is expected to compensate for the run that came before.
If the trials are independent and the probability is constant, past outcomes do not change the next one: a coin has no memory. Frequencies even out not by paying back a debt but by diluting the run in the mass of new trials. The mirror-image extreme is belief in the “hot hand”, where a run is taken as proof of a regularity. Both versions place the same undeclared bet on a model, which is why the first thing to check is not the length of the run but the assumption of independence itself: a real process can be autocorrelated, worn out, or dependent on a shared resource.
Claim. In the lottery the number 17 has not come up for five draws in a row.
Move. So 17 has a better chance now — it is already “due”.
Why it is a fallacy. The ball does not remember previous draws: the probability is the same as it was the first time. There is no force that evens out frequencies over a short stretch; equal frequencies arrive in the limit, not in the next draw.
At work. “Four quiet nights on call — tonight it is bound to blow up”, and its mirror image, “ten green builds in a row, the pipeline is stable, we can drop the checks”. Both conclusions take independence on faith. The opposite move is more useful: if a flaky test failed in 4 cases out of 100 and today it failed three times in an hour, the probability of that under independence is negligible — so the trials are dependent, and you should be looking for a shared resource, a neighbouring deploy or connection pool exhaustion. Same with retries: a run of timeouts is usually not bad luck but saturation. Work out the expected run length at your base rate and compare it with the observed one.
What to answer. Are the trials here really independent? If they are, the past does not affect the next outcome; if they are not, the run tells you the process has changed, not that chance owes you anything.
Cherry picking
cherry picking · подавленное свидетельство · suppressed evidence
Only the confirming part of the available data is shown, and the equally weighty part that refutes it is passed over.
The selection makes the sample unrepresentative not by accident but on the criterion of agreeing with the thesis, so the conclusion is fixed by the procedure rather than by the data. The competing explanation is always the same one and always off-screen: the observations that were not selected. Particular forms are a convenient time window, showing only the cases that survived (survivorship bias), and p-hacking, where the flexibility of the analysis is used until the required result comes out. It differs from honest selection in that the criterion was formulated after looking at the data and was never disclosed.
Claim. An acquaintance recommends an online course and sends over five glowing reviews.
Move. The reviews are excellent, so the course works.
Why it is a fallacy. The five reviews were picked out of hundreds, and picked by someone with a stake in it. What is not shown is the share who dropped out in the second week, the negative reviews, or the people who finished and changed nothing in their work.
At work. In the release report: conversion +12% over a chosen nine days. Off-screen: the window starts right after a disastrous Monday, a discount mailing landed inside it, retention and refunds are not shown, and out of twenty metrics two are quoted. Same in benchmarks: our system on our own load profile, theirs on the default config and without warm-up. The defence is procedural: the primary metric, the window, the guardrail metrics and the stopping rule are fixed before the experiment, negative results are published on the same footing as positive ones, and the raw data sits next to the conclusion.
What to answer. What data of the same quality did we not show? Were the metric and the window chosen before we saw the result?
Retrospective determinism
retrospective determinism · «это было неизбежно» · нарратив неизбежности
From the fact that an event happened it is concluded that it could not have failed to happen.
The outcome that materialised looks like the only possible one because the alternative branches are no longer observable: we see a single trajectory and build a coherent explanation to fit it. Two mechanisms are at work — hindsight bias, which rewrites the memory of what was expected before, and the narrative pull towards explaining an outcome by a chain of steps that “led” to it. The competing explanation is simple: the probability was middling, and one branch out of several is the one that came true. The test is what estimates were given before the event, not how smoothly the story reads afterwards.
Claim. Two people struck up a conversation by chance in a queue, and a year later they married.
Move. They were meant to meet, everything was leading up to it.
Why it is a fallacy. The inevitability was assigned after the fact: the thousands of queues where nothing happened never make it into the story. The event occurred — it does not follow that its probability was high.
At work. After an incident the walkthrough sounds like “that architecture was bound to fall over sooner or later”. Maybe; but the same logic explains the three preceding years, when it did not fall over, just as smoothly. The damage is twofold: the team rewrites something that was not the main contributing factor, and at the same time loses the ability to tell genuinely high risk from an after-the-fact explanation. The antidote is to write forecasts down with probabilities in advance: a decision log when the choice is made, a premortem before launch (“imagine this fell over six months from now, name the reasons”), and after the incident compare against the records. Then you can see whether the failure was predicted or the inevitability was painted in afterwards.
What to answer. Do we have a record showing that before the event we thought this outcome likely? Which branches were possible then, and what exactly closed them off?
Fallacy of the single cause
causal oversimplification · single cause fallacy · поиск виноватого
For an outcome with several interacting causes one is named, and the explanation is treated as finished.
Complex outcomes usually come out of a coincidence of conditions, none of which is sufficient on its own. Naming one factor does not rule out the rest — and, worse, it stops the search. Here the competing explanations are not alternatives but additions: part of the contribution belongs to a common cause, part to selection, part to coincidence. A distinct variety is reducing a multi-factor outcome to a culprit: that shifts the conversation from the mechanism to the person and usually ends the walkthrough before it has begun.
Claim. The dinner burned, the guests left early, the evening was a failure.
Move. It is all the oven — it runs too hot.
Why it is a fallacy. Several things came together at once: a new recipe, the timing worked out for a different portion size, no timer set, and guests invited on a weeknight. The oven may have been part of the explanation, but on its own it does not produce this outcome — and having named it, the hosts never checked the rest.
At work. “The cause of the incident was a heavy SQL query.” Four more conditions usually lie right next to it: the index did not make it over with the migration, retries without backoff, a connection pool of 20, and an alert with a threshold above the real SLO. The incident happened because all five coincided; removing one lowers the probability but does not close the failure class. That is why a post-mortem records contributing factors and chains of mechanisms rather than a single root cause: “five whys” down one branch gives a narrow fix and a false sense of closure. The same slip at a different scale — “the project failed because of the architecture”, with demand, deadlines, budget, dependencies and governance left off-screen.
What to answer. If this factor had been absent — would the outcome definitely not have happened? What other conditions had to coincide for it to come out exactly this way?
Language and authority
The argument rests not on the claim but on the word it was named with, or on the source it came from.
Appeal to authority
argumentum ad verecundiam · appeal to authority · ложный авторитет
Instead of a ground, the name of whoever said it is produced.
The fallacy does not begin where an expert was cited, but where the citation took the place of the argument. Three typical forms: the authority speaks outside their own field; their opinion is presented as proof rather than as evidence; the source is not named at all — “scientists have proved”, “everyone in the industry knows” — and is therefore uncheckable. The legitimate case is the exact opposite: the specialist speaks within their qualification, the field does not seriously dispute them, conflicts of interest are visible, the opinion is relayed in context, and the primary data is unavailable or expensive. Then “X thinks so” is a normal ground for believing with a caveat, but not a ground for forbidding a check.
Claim. The stain on the bathroom ceiling is most likely from a leak upstairs.
Move. My dentist said stains like that are always from condensation.
Why it is a fallacy. A dentist is competent about teeth; on damp in a ceiling slab his word is an ordinary private opinion, and it has crowded out the simplest step: go up to the neighbours and look. Had the same thing been said by a roofer who has fixed a hundred such ceilings, it would be evidence, a reason to check his version first, but still not a substitute for the inspection.
At work. “The chief architect said so” closes a question about response time that a twenty-minute measurement would settle. A distinct variety is the anonymous authority: “it is best practice”, “a big company has been through this already” — with no name, no scale, no version and no conditions under which it was actually tested. Where a metric is available, a reference to a person is always a weaker ground than a number.
What to answer. “Is this his field, and what data was he relying on?” If the primary measurement is available, take it rather than relaying an opinion.
Appeal to nature
appeal to nature · argumentum ad naturam · натуралистическая апелляция
From the fact that a thing has been called “natural” it is concluded that it is good.
In an argument the word “natural” means several incompatible things at once: arisen without human intervention, familiar, biologically determined, harmless, environmentally sound. The argument rests not on any one of these meanings but on the positive colouring the word carries in all of them. The value of a thing does not follow from its origin: hemlock is natural, antibiotics and encryption are not. The mirror form — “artificial, therefore harmful” — is the same substitution with the sign reversed.
Claim. The pie dough needs baking powder.
Move. No chemicals, better to use a starter — that is natural.
Why it is a fallacy. “Natural” has been substituted for an answer to the question actually being decided: taste, time and how predictably the dough rises. Soda and a starter differ in the chemistry of the process and in the timings, not in their degree of naturalness, and that is what the argument should be about.
At work. “A manual deploy is more honest — a live human is watching”, “this framework forces you to write unnatural code”, “organic growth is better than paid”. A manual step is not safer than an automated one by virtue of being natural: what gets compared is error rate and time to recovery. Until a concrete property being degraded is named — readability, coupling, cost of a change — “unnatural” means “unfamiliar to me”.
What to answer. “Which property are we actually discussing — safety, taste, price? Let us name it and compare directly.”
Argument from incredulity
argument from incredulity · argumentum ad ignorantiam personalis · апелляция к личному недоверию
“I cannot picture it” is presented as “it cannot be so”.
The premise is about the state of the speaker's imagination, the conclusion about the way the world is put together; there is no step between them. Difficulty in imagining a mechanism is information about what the disputant knows, not about the phenomenon. The mirror form is “there is no other way to explain it, so my version is right”: a shortage of imagination is turned into proof of the only alternative. The source of the argument here is the speaker himself: he offers his own experience as the boundary of the possible.
Claim. The teenager next door built himself a computer out of parts.
Move. Come off it. At his age I could not plug in a mouse. Someone must have built it for him.
Why it is a fallacy. One's own biography has been declared the measure of what happens in the world. This is checked without any guesswork by a single question: ask him to show how he picked the motherboard for the processor.
At work. “I do not believe this query runs in 8 ms, that does not happen” — and on goes the argument instead of a profiler and an execution plan. The same move in code review: “I do not understand how this works, so it is wrong”. Unclear code can be a real objection, but then the objection is phrased as “unreadable, rewrite it” and aimed at the form, not as “incorrect” and aimed at the behaviour.
What to answer. “What mechanism explains this, and what measurement would check it?” Not understanding something is a reason to ask a question, not a ready-made conclusion.
Equivocation
equivocation · эквивокация · подмена значения термина
The same word means different things in two premises, and the conclusion uses both meanings at once.
The term quietly changes its extension between the premises: wide in the first, narrow in the second, and the link holds only on the coincidence of letters. The marker is a word that has both an everyday and a technical meaning: “free”, “open”, “average”, “normal”, “safe”. The cure is indexing: write out freedom₁ (the absence of any restrictions) and freedom₂ (the ability to make a choice) — after that the step disappears along with the conclusion.
Claim. In the reading room you may not talk or eat.
Move. Freedom is when there are no prohibitions. A library has prohibitions. So a library deprives people of freedom.
Why it is a fallacy. In the first sentence “freedom” is the absence of any restrictions; in the second it is the freedom to read and to hear yourself think. The rules restrict the first for the sake of the second; one word hid the fact that these are different things, and without it the conclusion does not go through.
At work. The word “done”. At standup it is “the code is written”, in a promise to the customer it is “it works for users”; the status in the tracker is set on the first meaning and the deadline is quoted on the second. Same with “stable” (does not crash / does not change the contract), “coverage” (lines executed / behaviour verified), “average response time” (mean / median / p99) and “secure” (no known vulnerabilities / audited).
What to answer. “In which sense is the word being used here? Let us write down both and see whether the conclusion stays true under each.”
Appeal to tradition
appeal to tradition · argumentum ad antiquitatem · апелляция к старине
“It has always been done this way” is substituted for a ground why it should be done this way.
The age of a practice tells you that it has survived some amount of time, not that it is the best available or that conditions have not changed since. The fallacy is when the length of service closes off the question “why exactly this way” and turns a habit into a norm. The legitimate case is a different one and has to be named: a practice applied for a long time under the same conditions with no noticeable failures is real, if weak, evidence that it works; Chesterton's fence belongs here too — before you remove a rule, find out why it was put up. The difference lies in whether the length of service is cited as data about how it works, or as a ban on discussing it.
Claim. Maybe this year we do the holiday at our place instead of driving halfway across the country?
Move. We have gone to grandmother's for thirty years. It is a tradition.
Why it is a fallacy. Thirty years is evidence that it suited everybody, and a hint at a real value behind the tradition. But as an argument the length of time is offered in place of that value: conditions have changed, there are two children now, the drive takes a full day. A substantive answer would be “it matters to grandmother that everyone comes” — and that can be discussed.
At work. “We have always deployed this way”; “we do not touch that script, it has worked since 2016”. The second is not an empty argument: the script has been through hundreds of releases, and that is data about reliability. It becomes empty when it blocks the question of what the script does and why it fails once a quarter. The symmetrical trap is throwing an incomprehensible step out of the pipeline without finding out which incident once gave rise to it.
What to answer. “What exactly does this practice prevent? If there is an answer, let us write it down and check whether it still holds today.”
Moving the goalposts
moving the goalposts · передвижение ворот · подмена критерия
A condition was named, the condition was met — and then the thing under discussion is quietly replaced with another.
The mechanics are the same as in equivocation, except that what is swapped is not the meaning of a word inside the inference but the subject of the dispute as a whole: the agreement was about “will make it by Friday”, and what gets checked is “but what about quality?”. The new requirement may itself be reasonable; the fallacy is that the previous one was declared sufficient and was then withdrawn retroactively, with no explanation of what changed. The mark that separates the substitution from an honest clarification: there is no result the disputant would agree to count.
Claim. I will change your wheel for you in ten minutes.
Move. — Done, there you go. — You changed the wheel all right, but you did not balance it, so you cannot actually fix a car.
Why it is a fallacy. The promise was about a wheel and ten minutes; the test is suddenly about “can he fix cars at all”. The second question is legitimate in itself, but it is a new one, and it had to be asked before the first was carried out, not after.
At work. “Show me a benchmark” → shown → “but that is not prod” → canary shown → “we need a year of observation”. The second form is swapping the metric: p99 was agreed, the report has the mean, and the discussion drifts off into “on average it is better, though”. The cure is a decision rule written down before the experiment: which number, on which data and over what period we count as sufficient.
What to answer. “We agreed on a different criterion. If it no longer fits, say what changed, and we will fix the new one before the next check.”
Definist fallacy
definist fallacy · persuasive definition · убеждающее определение
An evaluation is built into the definition in advance, and the argument is won before anyone has looked at the subject.
The definition stops describing and starts asserting: “micromanagement is the necessary supervision of irresponsible employees”. Anyone who accepts that wording has already accepted both the evaluation and the cause. A related form is a definition cut so that counterexamples cannot fall inside it. There is a single mark: a contested thesis follows from the definition without a single observation. A neutral replacement describes what is observable (“detailed control of decisions with low autonomy for the person doing the work”) and leaves the evaluation to a separate proof.
Claim. The flat renovation took three months instead of one.
Move. A good tradesman is one who finishes on time. So he is no tradesman, and there is nothing to discuss.
Why it is a fallacy. The definition is built so that the question of what caused the delay — a late delivery, hidden wiring, a brief that changed three times — cannot even arise. The neutral description “the work took 90 days against a plan of 30” leaves room for a check.
At work. “A senior is someone who does not ask questions”; “good architecture is architecture with no coupling”; “a bug is what has been filed in the tracker, anything else is not a bug”. The last one is particularly hardy: a definition like that makes the goal of “zero bugs” reachable without a single change to the code — you just do not open the ticket.
What to answer. “Is that a definition or already a conclusion? Give me a description the evaluation does not follow from automatically, and we will discuss the evaluation separately.”
Etymological fallacy
etymological fallacy · appeal to etymology · апелляция к происхождению слова
From the origin of a word it is inferred what the thing it names is obliged to be.
The meaning of a word is set by how it is used now, not by what it grew out of. “Data” comes from “given” — but the objectivity of data is determined by the collection procedure, not by the root. Etymology is useful as the history of a concept and as a hint at which metaphor was once chosen; it does not establish the properties of the thing. The negative form of the same move: “the word originally meant something else, so you are saying it wrong” — usage changes, and that is not a mistake by the speakers.
Claim. Let us have a romantic dinner with candles.
Move. “Romantic”, strictly speaking, comes from Rome, from the Romance languages. What have candles got to do with it?
Why it is a fallacy. The word travelled from “written in the vernacular” to “about love and feeling”; today's meaning is set by usage, not by the Roman root. Arguing about the root does not undo the fact that both speakers understood perfectly well what kind of dinner was meant.
At work. “A microservice has to be micro — yours is four thousand lines, that is not a microservice”: the prefix has become the criterion instead of the ownership boundary and independent deployment. People argue the same way about serverless (“but there are servers in there!”), continuous integration and agile — instead of discussing the practice they discuss how faithful the name is to it.
What to answer. “How is this term used here today? Let us fix that meaning — the history of the word has no bearing on the dispute.”
Reification
reification · hypostatization · гипостазирование · конкретизация абстракции
An abstraction is treated as a thing with a will, a location and demands of its own.
A name invented for convenience of description starts acting as a subject: “the market demands”, “the process decided”, “the architecture does not allow it”. It is always something concrete that demands — a person, a document or a constraint that can be named — and substituting the abstraction removes from the conversation the party you could argue with. The second form is an indicator turned into an entity in its own right: “let us raise engagement”, where engagement exists precisely as a formula over the logs. The check: replace the abstraction with the mechanism and see whether the claim still means anything.
Claim. I want to put a wardrobe sixty centimetres deep in the hallway.
Move. The design of the flat does not allow it.
Why it is a fallacy. What does not allow it is not “the design” but the width of the passage, a door that has to open, or somebody's intention. Until it is said what exactly is in the way, there is nothing to object to: the abstraction has been handed down as a verdict. If what is in the way is taste, that is an argument too — but a discussable one.
At work. “The architecture requires a separate service” — what requires it is the person who took the decision, or a constraint that can be named out loud. And the metric that became a target: velocity was invented as a description of pace, but as soon as a team is judged by it, what grows is the estimates on tasks, not the output. Same with “80% coverage” and “time to first response on a ticket” — the measurable shadow of the object takes the place of the object.
What to answer. “Who exactly is requiring this, and on what grounds?” For a metric: “what happens to the object itself if the number goes up and the behaviour does not change?”
Appeal to consequences
appeal to consequences · argumentum ad consequentiam · аргумент к следствиям
The unpleasantness of the consequences is passed off as the falsity of the claim, their pleasantness as its truth.
The truth of a claim and the desirability of what follows from it are different questions, and this argument glues them together: “if that is true we will have to redo everything, so it is not true”. The only thing working here is the reluctance to redo it. A legitimate and completely different thing is an argument about a decision: consequences must bear on what to do, but not on what is actually the case. There is a single test: what is the dispute about — a fact, or a choice of action.
Claim. It looks like a pipe is leaking behind the bath — the neighbours below have a stain on their ceiling.
Move. Impossible. Otherwise we would have to take up the tiling, and we spent a month laying it.
Why it is a fallacy. The cost of the repair says nothing about the state of the pipe: it is either leaking or it is not. Talking about the tiling is appropriate when deciding whether to fix it now or after the holiday — but not when establishing whether there is a leak.
At work. “If we call this defect a blocker the release slips, so it is not a blocker”. Severity is determined by the impact on the user; the release date is a separate decision that can be taken deliberately and with a known risk. The inverse form: “this design gives us tenfold headroom, therefore it is the right one” — the desired result has been substituted for an assessment of price and risks.
What to answer. “Are we arguing about how things are, or about what to do? Let us establish the fact first, then decide what to do about it.”
Appeal to novelty
appeal to novelty · argumentum ad novitatem · аргумент к новому
“This is newer” has been substituted for “this is better”.
The release date is not the property you are paying for. A new solution may lift an old constraint, or it may simply not have had time to accumulate known problems: it has less operational experience behind it, and novelty means uncertainty rather than an advantage. The argument becomes substantive when it is said what exactly changed and at what price; and it stays empty as long as it rests on the single word “modern”.
Claim. We need a kettle to replace the burnt-out one.
Move. Get the one with the touch panel, it is the latest model.
Why it is a fallacy. The year of release says nothing about how fast it heats, or about how long a touch panel lasts in a steamy kitchen. The argument would become substantive like this: “the new models have a different heating element, less scale builds up” — and that can be checked.
At work. “We are moving to a new build system, the old one dates from 2015”. Age is not a defect in itself: with an old tool the workarounds are known, the bugs have been found and the support is predictable. The comparison runs on named items — build time, reproducibility, migration cost — and you separately allow for the fact that the new solution's bugs simply have not been found yet.
What to answer. “What specifically changed in the new version, and which of our problems does it solve?”
Chronological snobbery
chronological snobbery · presentism · снобизм современности
A claim is rejected for being old — as if a later era had already refuted everything that came before it.
The judgement moves from the content to the date: “that is how people thought in the nineties”, “that is a last-century approach”. What is swapped here is the source — an era is passed off as the body that hands down the verdict, although verdicts are handed down by observations. It differs from the appeal to novelty in direction: there the new is praised, here the old is discredited, but both lean on a position in time instead of a walkthrough. The argument becomes substantive exactly when it is said which observation or which constraint has changed since.
Claim. By grandmother's recipe the dough has to stand for an hour in a warm place.
Move. That is last century, now it is all done with a food processor in five minutes.
Why it is a fallacy. The hour is needed by the yeast, not by the tradition; a processor speeds up the mixing, not the fermentation. The claim can be refuted by the properties of yeast and by temperature — but not by the age of the recipe.
At work. “A relational database is an outdated approach”, “server-side sessions? that is how it was done before SPAs”. The age of a solution is not an argument; the argument is which constraint disappeared: memory got cheaper, replication appeared, the load profile changed. The other side: old texts about reliability and the complexity of systems have not gone out of date, because they describe properties that do not depend on the fashion in tools.
What to answer. “What have we learned since that makes this wrong?” If there is no answer, age has no bearing on the matter.
What’s next
The reference concludes the logic course. Further, it is more useful not to read about fallacies, but to catch them in real materials:
- Walkthrough of your argument using a card — in the workshop.
- Causality and statistics in engineering decisions — “Causal, probabilistic, and statistical fallacies”.
- How all this looks in scientific and engineering arguments — the corresponding chapter.
- How to search for and verify sources you rely on in an argument — track “How to search for information”.