Welcome to the QA Tech-Tips blog!

Some see things as they are, and ask "Why?"   I dream things that never were, and ask "Why Not".  
Robert F. Kennedy

“Impossible” is only found in the dictionary of a fool.  
Old Chinese Proverb

Sunday, February 6, 2011

The Sky is Falling! The Sky is Falling!

Today's post was inspired by the paranoia some people have about computers and the information they send.

The basic thrust of today's posting is this:

Unless you happen to be the Department of Defense, a Multi-National Bank with zillions of dollars in assets, or a company of some note that might be a target for Industrial Espionage, the chances of anyone giving a hoot about you, or your information, are slim to none.

Of course, you do need to take sensible precautions.  You would not go to the local super-mall, and leave your car unlocked; you lock your house when you leave and you don't leave expensive and valuable items just laying around to tempt fate.

To put this in perspective, if someone REALLY wants your butt, they're going to have it, no matter what you do.

In other words, if determined people can hack into sites like the Department of Defense, Citibank, or the New York Times - with their multi-layered defenses - there's not much you can do to make your computer more secure than that.

The other side of that statement is this:
These are high profile targets.  Hackers get a lot of "street-cred" by being able to hack a secure installation.  Crooks can use this to transfer millions of dollars to numbered off-shore bank accounts, or steal sensitive military secrets.

Think about it.  How much respect is a hacker going to get by saying "Oooh! I just hacked Mrs. Johnson's Linksys router!!"  It's virtually a lead-pipe cinch that Mrs. Johnson doesn't have millions of dollars laying around to wire to an off-shore bank either.  So, by and large, the hackers and script-kiddies really could care less about you.

What you should do is take reasonable and sane precautions, the same as you'd do with your home or car.
  • You don't connect a computer DIRECTLY to the Internet without a hardware firewall between you and it.
  • You don't send potentially sensitive information such as passwords, SSN's, credit card numbers, etc. in clear-text.  If you absolutely MUST send sensitive information by e-mail, you can exchange public keys with the recipient and send encrypted mail.
  • You make sure any wireless routers you have use strong encryption and a strong passphrase.
  • You make sure your computer is up-to-date with the latest security updates.
  • If you have a laptop, and you use it in public places, you make sure you have a good software firewall installed.
  • And you make sure your anti-virus and anti-slimeware software automatically update themselves so they remain up-to-date..
If you are the typical  computer user, this should be enough and more than enough to keep you and your sensitive information safe.

Remember; you need to view all these recommendations as just that, recommendations and you should apply them to your specific situation.

You don't have wireless?  Then that part doesn't apply to you.

You don't use public WiFi hotspots?  Then you don't have to worry about a rogue hotspot trashing your computer.

Just like the automobile advertisements say - Your Mileage May Vary.  Adopt what you need to adopt and don't worry about the rest.

If you really want a belt-and-suspenders security plan, you don't store sensitive information, (such as electronic copies of your tax returns), on your local computer - you write them to disk and file them away.

Of course, there are other things you can do as well.  You can virus-check incoming e-mail.  You can check for attacks from rogue web-sites and you can check for suspected spyware.

Bottom line:  Take reasonable and sensible precautions.  Don't be stupid, but don't get hyper about every little thing either.

Above all, enjoy the technology that lets you see and talk to your darling kids/grandkids who are 8,000 miles away, in real time.

What say ye?

Jim

Friday, December 10, 2010

This is *NOT* a drill - Repeat, this is *NOT* a drill.

You've seen 'em.  E-mails that claim things like: "If you don't send this to 20 people in the next 10 minutes, a big hairy monster will crawl out of your monitor and STICK HIS TONGUE OUT AT YOU!!!!!!!!!!!"

And yes, if that happens, you can honestly claim a Real Bigfoot Sighting.  Be sure to let the Enquirer know too. . . .

If I had $20 for each of these idiot messages I received, I would be a Gazillionaire, and would be sending you this Tech Tip while seated in my chaise-lounge, sipping margaritas, on my private island in the Mediterranean.

However, this one is different.

My wife got an e-mail today from her boss - which contained a link to a news story.  Having worked with RFID technology for years, I would believe this so fast it would make your head spin.

The gist of it is this:

First:  Do you have any credit-cards with this symbol on them?





Here is an example of a credit card with that symbol on it. . . .




(I just received this to replace my Midwest Airlines credit card.  I like it because it has a cat. . . a BIG cat. . . on it!)

Note the RFID symbol circled in red

Second:  Do you carry them with you?

If so, than there are ways that people with simple, inexpensive scanners in something as small as a fanny-pack can grab your credit card info without you even knowing that they grabbed it.  It's a new technique called "Electronic Pick-Pockets"

If you carry a newly issued passport, they can grab more than just your credit card number too. . . .

WOW!

Go visit this link if you don't believe me.

http://www.wreg.com/videobeta/8ba6f8fc-90a2-4711-90ea-1884ec348310/News/

I normally don't go for stuff like this, but THIS one scares me.
Solution:
  1. Wrap your card(s) in aluminum foil
  2. Slip them into a small metalized anti-static sleeve.
  3. Leave them at home, and ask your credit card company for one that's NOT RFID.
Please?

I really don't want to see you get ripped off for Christmas

Jim

Sunday, November 21, 2010

Is it Time to Reinvent the Wheel?

Note:  The following article originally appeared in the November 18th issue of the uTest Newsletter.
If you're curious, you can find it HERE.
___________________________________________

Our latest guest post comes from Jim “JR” Harris, Principal Engineer and Owner of Arrowhead Computer Consulting, and one of the most entertaining tester bloggers out there (you’ll see what I mean shortly). You can find more of his writings at qatechtips.blogspot.com. In this post, he addresses why the value created by testers is not always fully recognized in the world of business. Enjoy!
____________________________________________
 
In the October issue of the uTest newsletter, Matt Johnston led off with the title “Are Testers the next Endangered Species” – and I blew my stack!  Now don’t get me wrong; it’s not like I was furious or anything like that, but I will admit that I did bite the heads off of about a dozen or so thick framing nails before I could compose a coherent reply.

And I let him have it – with both guns blazing! – eager to defend the honor and integrity of those of us in the Software QA community.

“Oh, it’s the idiots in Management who don’t recognize the need for quality software!”

“Those idiots in Marketing ALWAYS leave us with too much to do and too short a time-line to do it!”

“If the developers would send us software releases that were at least testable; we wouldn’t be in this bind all the time!”

Now Matt has a sick and twisted sense of humor, not unlike my own.  So instead of getting offended, he offered me the chance to express MY views on his bully pulpit.  “Ok Einstein, you’re so smart?  YOU write the next one!”  No he really didn’t say that, but his invitation was clear:  Put up or shut up.

I got ready.  Cleaned both pistols, checked all my ammo and was ready to sit down here and burn a hole in his newsletter servers.  Pistols cocked, take careful aim and. . . . .

Then I started thinking.  (Always a good idea, that – thinking, that is.)

What was I aiming at?  Management?  Marketing?  Developers?  Or maybe, just maybe, it was at my own two feet.

Then I started thinking some more.

What is management’s mandate?
Their job is – first and foremost – to make money for the company.  You know, Money.  Moola.  Cash.  As in “to pay your salary”, or to be able to afford that nice new Blade Server you need for the next round of testing.

What about marketing?
Nope.  “Make QA happy” does not appear anywhere in Marketing’s job description.  It reads more like “Make past, (and future), customers drool over the thought of shelling out huge dollars to buy our next release.”

Development?
Who are YOU kidding!  They get it as bad as we do – six months’ worth of coding due in six weeks.  Then pray to the Blessed Virgin that it doesn’t fall into a million pieces when QA gets it.

So where does that leave us?
Let’s look at it from upper management’s perspective:

To them the world is black-and-white.  Things either cost money, or they make money.
  • Of course, Management is always important.
  • Marketing drives sales.  Sales = Cash.
  • Development actually creates the product that the company sells.  Product = Cash.
Then, there are the expenses:
  • Housekeeping.
  • Electric, gas and water.
  • Rent.
  • Capital equipment.
  • Maintenance.
And waaaay down at the bottom of the heap:
  • Tech Support.  (They gripe too, but not as bad as QA.)
  • QA:  The guys that are never satisfied and always gripe about SOMETHING!
And you wonder why we’re not popular in the corporate world?  Puh-leeeze!

So there you have it.  It really does make sense when you look at it this way

Our problem is this:  We have never really presented ourselves as an asset to the company.  Rather we’re seen as being more like “going to the dentist”; you gotta do it, but you aren’t expected to be overjoyed about it.  We’re not only viewed as a “sunk cost” – we’re a “sunk cost” that complains all the time!

So why are testers expendable?  Because we’re not perceived as driving value to the company.  And that’s the problem.

Next question:  How do we go about fixing this?

Answer:  Change. Grow. Demonstrate to the rest of the company that we’re assets that drive value, not just “the gripe-and-moan department.” It won’t be easy, but it’s something we have to do if we want to survive.

First:  Lose the whining and complaining.  The next time you get riled up at something and want to start complaining, put your hand in your mouth and bite. Hard. Then remember that the pain you’re feeling is just a small sampling of the pain you are causing others.

Second:  Trim your claws and fangs.  If YOU had spent three or four sleepless nights getting that code segment finished on time, would YOU want some “idiot from QA” coming to you and telling you it’s a piece of junk?

Next:  Try to become a pleasure to work with, not a pain in the butt.  Think of how you can present your issues as something other than a gripe-session.
  • Can you offer the developer some positive feedback too?
  • Can you offer a constructive suggestion to improve it?
At your next team/department meeting:
  • Ask if there is something QA can do to actually HELP the development process.
  • Maybe participating in early stage code reviews would help?
  • Maybe participating in early stage design or requirements reviews would help?
By doing this you may be in a position to recognize a mistaken assumption, or a misunderstood requirement. When we solve these problems early on, we help reduce the pain felt in both Development and QA later. More efficient and accurate work = More Money.  More Money = We drive value.

We need to be vigilant in reminding our boss, (and our boss’s boss), how critically important a firm commitment to quality is in today’s litigious world.  (i.e. Toyota, etc.)  By reinforcing that commitment we reduce legal risk and expense.  Reducing expenses = More Money.  More Money = We drive value.

We need to be vigilant in reminding ourselves, as well as others, that we’re not the only fish in the pond. If we produce shoddy products, we drive our customers to our competition.  Likewise, excellent products drive the competition’s customers to us. More Customers = More Money.  More Money = We drive value.

Maybe, just maybe, we need to take a good hard look in the mirror. Maybe the reason that “testers” are becoming “endangered” is because we’re driving ourselves to extinction by not changing to keep up with the needs of the companies that hire us.

Maybe it IS time to get out that stone axe and re-invent the wheel.


What say ye?

Jim

Friday, October 22, 2010

Quality *IS* Important! (Believe It or Not)

Today's topic is one that is a lot like the weather:  Everybody talks about it, but nobody does anything. . . .

Toyota recalling zillions of cars, people afraid to eat eggs or peanut-butter because of some bizarre disease it's probably carrying.  Other manufacturers in hot pursuit of Toyota's massive recall record.  And so on.  You can hardly open a newspaper, (or go on-line), today without hearing about how something, somewhere, is causing untold grief.

Then, Matt Johnston over at uTest sent out a newsletter with the subject line: "Are Testers the Next Endangered Species?"

And WHY might "testers" be an "endangered species"?  Easy.  Most companies pay only lip-service, if that much, to the idea of actually producing a quality product.

To them, QA's job is to lick the development manager's boots, praise him to the sky, and be willing to take a beating whenever something goes wrong.

I've been looking for QA work for more than three years now - and I've seen many QA positions cross my inbox.  From the way the requirements for the position were written, it's easy to tell that they really don't want trained QA people, they want burned out developers.

So, in my humble opinion, the biggest threat to the software industry isn't the lack of COBOL programmers as one pundit put it, but rather the lackadaisical attitude that most companies, and most managers, take toward quality.


This is a picture taken in January of 1990 after an Avianca airliner crashed into a hillside in Cove Neck, Long Island after running out of fuel.  (See the source web page at http://www.airdisaster.com )  Experts say that better training for both the pilots and ground controllers would have likely eliminated this accident.  Wikipedia has an article about it HERE


Here's another one.
Back on April 10th, (2010) one of the best people I ever knew smashes into a centuries-old oak tree in Spencer, Ma., travelling fast enough to absolutely obliterate the heavy-duty Toyota Tundra pickup he was driving.  A software glitch?  We'll never know, but Toyota was recalling Tundra pickups, including this one's model year, for "unexplained acceleration".  (Photo by Melissa Mckeon - The Landmark newspaper)

I could go on and on - these are ones from my own personal experience.  I was working for a company on Long Island that manufactured fuel systems for planes like this when the Avianca airliner crashed.  The man driving the truck was a good friend of mine, he never hesitated to offer a hand whenever needed.

People think it doesn't matter.

"Oh, it's just a browser crash."
"Damned Windows O/S!  Reboot and it will be OK."
"Stupid network glitch. . . .!!"

I hate to break the bad news to you folks - take a look at those pictures again - quality DOES matter.  The "little details" DO matter.  Those little things that get swept under the rug in the name of "meeting deadlines" and "not slipping the schedule" DO have consequences.

Sometimes fatal ones.

What say ye?

Jim