Live data from Hacker News

History's Worst Software Bugs (2005)

archive.wired.com

31–34 of 34 posts

Re: History's Worst Software Bugs (2005)

#31

   Startup Weekend entrepreneurial event on alert after man threatens explosions, guns
http://www.oregonlive.com/portland/index.ssf/2012/04/startup...

In reality I was lecturing the Starup Weekend corporation on Engineering Ethics. I'll explain in more detail some other time on my own site, then submit the link.

I do not want to be specific about the bug I referred to when I tweeted that anyone with a basic understanding of computers could detonate a large industrial facility from the comfort of their own home, but I will say that the actual detonate is Trihedral Engineer's VTS HMI/SCADA industrial control systems product.

It has since been renamed "VTScada". I expect that's because I BCCed one of Trihedral's three partners, the one who does all their sales and marketing, on my eMail to New Orleans industrial control systems engineer Roger Williams in which I requested he forward my Kuro5hin diary about Glenn Wadden's Deep Insight Into The Nature Of Reality to his colleagues in the Gulf offshore oil industry.

http://localroger.com/

Roger's ROFFLECOPTER arrived in my Inbox twenty minutes later. He knew very well I had BCCed someone at Trihedral but he had no clue who it was. In his reply, Roger complimented me for my persuasive rhetoric, as well as pointed out that I was an even more effective troll than he was.

My bunker buster bug is easily patched but Trihedral has no way to verify that their users have actually installed their patches. Were I to point out how to exploit it, a great many large industrial facilities would detonate. You don't want to do that.

However I will point out some other, far less likel yet deadly bugs that, given VTS' steaming pile of C++ source, would be quite intractible to fix. Trihedral has no hope whatsover of fixing all of them without a complete rewrite:

    Jonathan Swift Sticks It To The Man
http://www.warplife.com/ethics/safety.html

> If the single installation of a Human Machine Interface / Supervisory Control And Data Acquisition product used to control a Giant Robotic Automobile Assembly Plant is not Exception-Safe...

            You Will Drop a Pickup Truck
           On One of Your Plant's Workers
     Thereby Making a Widow of His Wife Instantly.
I don't actually know that it's related, but not long after I published Stick It To The Man, CERT issued an advisory regarding VTS.

I don't actually know but assertively speculate that VTScada is that complete rewrite. I will give them credit for VTScada's far-richer user interface.

Insightfully well-designed and implemented UI is of vital importance to Human Machine Interface / Supervisory Control And Data Acquisition Products. Consider that Three Mile Island was the result in part of all the knobs in its control room being identical.

I once saw a photo of a reactor control panel where someone had replace all the knobs with beer keg tap handles. :-D

Re: History's Worst Software Bugs (2005)

#32
1993 -- Intel Pentium floating point divide error.

Here's a joke from 1993. It's been a good year for Andy Grove, CEO of Intel. They've rolled out the Pentium and it's been a big success. So he walks into a bar and asks the bartender for a shot of 22-year old Glenmorangie Scotch to celebrate. The bartender puts the glass in front of him and says, "that's $20, sir."

Andy puts a twenty dollar bill on the counter, looks at it for a moment, and says "keep the change."

Re: History's Worst Software Bugs (2005)

#33

Earlier quoted context omitted.

> I don't really know what expect in the wake of Y2K38 because it's about there, lurking in waiting. I've been wondering the same. The Y2K bug was easy for many places to fix. Granted I wasn't a profressional developer at that time but I've looked at historical fixes at the companies I have worked at and all of their solutions were pretty easy (change application code to use 4 numbers instead of 2, run SQL update scr…

The obvious fix is to use a 64bit integer to hold timestamps.

FWIW, the year 2027 has the same weekdays as 2038. If the worst comes to the worst, setting the clocks back 11 years on unremediated systems has a chance of allowing them to keep working.

Re: History's Worst Software Bugs (2005)

#34
post #20

Seem to me this list needs to incorporate how easily these bugs could have been avoided/detected/fixed, rather than just how dire the consequences were. It doesn't say much about what people did to test their code. For instance the first one in the list is something unit testing would have fixed. Take the trajectory function, plug numbers in, see if it's correct. Some of these things were a lot more obvious than othe…

Unit tests would be highly unlikely to catch most of those. "a formula written on paper in pencil was improperly transcribed", "neglect to properly "seed" the program's random number generator, A HW bug that's not close to obvious numbers to check, intentionally inserted bugs, input outside of the intended design, etc.

Correct. A unit test is a defect removal mechanism. What these faults needed was a defect prevention mechanism. One of those mechanisms is Design/Code reviews.

With all the emphasis on testing and TDD, etc, I get the feeling that reviews are getting the shaft. They are both important, for different reasons.

Post reply on HN