back

by colesantiago·5y ago·view on hn ↗
Why wasn't this bug caught in the first place and allowed to be rolled out into production?

This is very serious for everyone depending on signal, that I could just lose all my secure chat history without warning!

3 comments
Signal's inability to sync its history to somewhere else (e.g. their server, encrypted) and its rather inaccessible backup processes[1] are a pain. It makes me use something else for anything serious sometimes.

[1]: https://support.signal.org/hc/en-us/articles/360007059752-Ba...

What kind of a question is that? Are you a developer?

Do you think developers willingly write bugs into their applications, then simply release them hoping they can mess up somebody's day for the fun of it?

"Allowed to roll out into production" as if there's a manager looking at the list of newly created bugs, grinning and going "This bug... I like this bug! Roll it out!"

“Why wasn't this bug caught in the first place” - this isn’t an attack on whichever developer introduced the bug.

It’s a (totally fair) attack on Signal’s lack of QA/testing in their development + release cycle.

Do they implement peer reviews on PR? Multiple reviews on changes touching mission critical code (ie. data migrations)? Do their test suites provide adequate test coverage? Do they have a manual Q/A process that involves real people testing new releases?

Considering Signal’s funding, I would hope the answer to all of those questions is yes.

But if it’s possible to release code that completely corrupts the app with no known fix, I suspect their test coverage and Q/A processes aren’t as robust as they need to be.

Maybe all of those things. Given this issue isn't widespread AFAIS, it could have went through a bunch of tests and QA people, none of which caught the unique combination of factors that might be rare but not rare enough to not cause problems on a lot of devices regardless. They should totally improve their testing methodology after such a bug, but I can see how a perfectly competent dev team could let such a bug slip. I haven't followed Signal's track record though, so I couldn't say if this is a one-off or a pattern.
You're cutting a Dev team an awful lot of slack for a data loss bug.

Microsoft got rightfully roasted for last years data loss release. This is arguably the most serious class of bug, and the most preventable.

What are you talking about? They clearly didn't test this hard enough otherwise this would be caught early.

Was there any tests for this sort of thing? surely if you are storing secure chat history to a database this should be tested to death.

Had they tested more of this functionality this serious bug would have been caught, and now that I recommended this to people, I pretty much now regret doing so for secure messaging.

Well I guess that bursts the Signal hype brigade that Elon Musk, et al, and the media have started and you're required to sign up with a phone number which it then goes through your contacts list which already outrageous. Also, it turns out that you can't even sync your chat history, nor can you back them up easily on another device. So if you change your SIM, have your device lost or stolen, its all gone.

This right here was the final serious nail in the coffin that your chat history is corrupted due to this bug in production.

$60M in funding and they still can't fix these issues or handle these many users. I liked the Signal name and its friendliness to the end user, but I think the true hard-hitting reality is, it is just not ready yet for serious use. What a shame.