Практика Shadowing: 25 crazy software bugs explained - Изучайте разговорный английский по видео

Создание урока...
1
It's not a bug, it's a feature.
2
Programmers often use that excuse to justify their garbage code, and sometimes it actually works.
3
Like in the original Sid Meier's Civilization game, Gandhi's aggression level was set to an unsigned integer of 1, making him a super chill pacifist.
4
But when another civ adopts diplomacy, it reduces aggression by 2.
5
1-2 equals 255, or an unsigned integer underflow, which maxed out Gandhi's aggression and turned him into a diabolical thermonuclear enthusiast.
6
Civ players love this bug so much that it became a feature.
7
That's the urban legend anyway, but it's all fun and games until people start losing money and getting blown up in real life.
8
Real men test in production, and in today's video, we're going to take this carbon fiber submarine
9
and travel down the software bug iceberg to look at 25 examples of bad code that changed the world.
10
Where the deeper we go, the more severe the consequences.
11
If you survive until the end, you'll understand why to do fix it later might be the last line of code you ever write.
12
Our journey begins in the year 2008, a time when people still use devices like iPods to listen to music.
13
Microsoft had its own crappy knockoff called Zune.
14
The device worked great until December 31st, New Year's Eve, when every Zune around the world froze and became a very stylish brick.
15
The screen displayed a loading bar and would get stuck at 100% and then just stay there.
16
It could only be fixed manually by removing the battery.
17
This happened because it wasn't programmed to account for the extra day in a leap year.
18
When reaching the 366th day of a leap year, the software attempted to reset, but a logic error in handling the day count meant the device could not exit the loop, causing it to freeze permanently.
19
This code could be easily fixed by simply breaking out of the loop when the number of days reached 367.
20
But not all bugs are that easy to fix, like the infamous Pentium FDIV bug of 94.
21
Occasionally, when a program did floating point division on a Pentium chip, it would return an incorrect value.
22
It only happened in about 1 in 9 billion division operations, but was discovered by a professor at Lynchburg College while doing computational number theory.
23
Originally, he thought it was his own bug, but after extensive testing, he reported it to Intel.
24
Intel tried to downplay it, but then IBM suspended Intel chips in their PCs, and it turned into a massive PR nightmare.
25
The core issue is related to the SRT division algorithm, which is a way to speed up division by using lookup tables to estimate the next digit of a quotient.
26
The lookup table contains 1066 entries, but the problem in this bug is that 5 entries were missing,
27
causing certain combinations of numbers to return incorrect results at the hardware level.
28
That's pretty bad, but this next bug was found inside an Apple.
29
In 2019, you could use your iPhone to start a FaceTime call with someone, then while the call is ringing, swipe up to add another person making it a group call, add your own phone number as an additional person,
30
then FaceTime would glitch out and think the group call was active.
31
And now you can eavesdrop on the audio from the original recipient's phone.
32
And then if the person pressed the power button to dismiss the call, it would activate their camera.
33
What's even crazier is that this bug was discovered by a 14-year-old
34
while trying to set up a group chat for playing Fortnite.
35
Then he tells his mom, and his mom tries to report it to Apple.
36
Apple thinks its code is perfect and just ignores him, but then, about a week later, the bug starts to go viral on social media, and everybody's doing it on live streams.
37
At this point, Apple disables Group FaceTime entirely, and released a patch about a week later.
38
They did make things right with the 14-year-old, though, and awarded him a bug bounty and some education funding, but the root of the problem appears to be the fact
39
that they weren't checking the state of the call before activating the audio stream.
40
Normally, software bugs cause people to lose money, but sometimes, the opposite is true, like the 2024 Chase ATM glitch.
41
Most banking systems run on proprietary code that was written 50 years ago using ancient languages like COBOL.
42
Usually, when you deposit a check, it needs a few days to clear before you can withdraw those funds from an ATM.
43
But at JPMorgan Chase, some sort of glitch prevented this safeguard, and tons of viral videos hit TikTok of people withdrawing tens of thousands of dollars that they never had,
44
by simply depositing a fake check and withdrawing money right away.
45
I'm no fan of the banking system, but unfortunately, this also constitutes check fraud.
46
A few days later, these people had bank accounts deep in the red
47
and are now being sued by the bank and may face criminal charges.
48
That brings us to the end of tier one, and things are going to get a lot crazier from here.
49
But if you like crazy programming stories, a website you'll want to check out is daily.dev, the sponsor of today's video.
50
If you're learning to code or learning a new language or framework, it's the one place you can curate all the latest news, tutorials, videos, and content filtered by the topics you're interested in.
51
When you join a squad, it'll create a personalized news feed on that topic, but more importantly, connect you to a community of like-minded developers where we can all suffer together.
52
And these aren't bots, but real people of all skill levels who can help you build your network in the tech industry.
53
And did I mention, it's all entirely free, so check it out with my invite link at daily.dev slash fireship.
54
But now, it's time to dive below the surface into tier two starting with the AT&T long-distance crash of 1990.
55
Cell phones were hardly a thing back then, and if you wanted to communicate with someone outside of your village, you would have to pay for a long-distance network.
56
After a software update, a single faulty line of code caused a network switch to crash and automatically reboot.
57
One failed switch is no big deal, but when it would reboot, it would cause neighboring switches to fail as well, resulting in a cascade of failures that took out the entire network.
58
The bug was a C program that included a break statement within an if clause within a switch clause.
59
When a second message was received while the switch was still processing the first, the program dropped out of the if clause prematurely and overwrote crucial data, causing the switch to reset.
60
And this created a domino effect that blocked 50 million calls around the world.
61
A dropped call is annoying, but the last place you want to bug is in an aircraft, especially when it's in the oxygen system of an F-35 fighter jet.
62
In 2012, pilots were experiencing hypoxia-like symptoms during flights, like dizziness, disorientation, and overconfidence just like a drunk driver.
63
These jets have a complex oxygen generation system called OBOGS.
64
Usually it worked fine, but the underlying software wasn't robust enough to account for real-time variables like rapid altitude changes or variations in pilot breathing patterns.
65
When it comes to data, the old saying goes, garbage in, garbage out.
66
And when that data controls how much oxygen you get while flying a $100 million lethal weapon, you better be damn sure you test your code for all possible variables.
67
In this case, the code is top secret, but it's probably C++, and luckily nobody got blown up and it was later fixed with a software update.
68
Speaking of airplanes though, back in 2008, the 4.3 billion pound Heathrow Terminal 5 opened,
69
and it only took a few days for a software bug to result in over 500 cancel flights and 42,000 lost bags.
70
The new terminal had a complex automated baggage handling system with 30 miles of conveyor belts
71
and RFIDs and barcodes to manage up to 12,000 bags per hour.
72
When they pushed a prod, several different software systems failed to communicate.
73
Employees couldn't log in, RFID tracking systems couldn't track bags, among many other issues.
74
And this led to an entire breakdown of the system, costing 16 million pounds to fix, which is a prime example of when testing and production goes wrong.
75
But well-tested code breaks too.
76
In 1982, the Vancouver Stock Exchange began to slowly decrease in value due to a rounding error.
77
The error was so minor though, that nobody even noticed.
78
The value of the total index started at 1,000, but then over the course of two years dropped to 520, until one day somebody was like, what the hell is going on here?
79
It was a software bug, but had the index increased in value, it would have been a feature.
80
What happened was the software was truncating each stock price change to two decimal places instead of rounding.
81
One stock in an index of thousands only has a minor impact, but over time, it creates a cumulative rounding error.
82
And in this case, they had to completely recalculate the value of the index from scratch.
83
And that brings us to November 1988, when Robert Morris accidentally created the Morris Worm on this here floppy disk.
84
Morris was not an evil hacker, but a graduate student at Cornell, who released a self-replicating computer program designed to gauge the size of the internet, which was tiny back then,
85
but it rapidly spread across Unix-based systems, and crashed thousands of computers in the process by overwhelming their resources.
86
It took out 6,000 computers, which at that time was around 10% of the total internet.
87
The worm itself exploited weaknesses in things like the SendMail protocol and a buffer overflow vulnerability in the Finger program, which provided information about users on the network.
88
The program would then execute code remotely on these machines and send itself to other machines on the network.
89
His plan almost worked, but there was a bug in his code that would reinfect the same computer over and over again.
90
Eventually, it took out MIT, UC Berkeley, and NASA, and resulted in Morris getting the first felony conviction under the Computer Fraud and Abuse Act.
91
But now it's time to dive deeper into Tier 3, where things actually start to blow up, like NASA's Mars Climate Orbiter in 1999,
92
which torched $125 million in taxpayer money when it burned up entering the atmosphere of Mars.
93
And that happened because one software team used imperial units, pound force, while the other team used metric units, newton seconds.
94
And that's kind of a big issue when it comes to space travel, especially when just a few years ago, in 1996, bad software caused the Ariane 5 rocket to explode.
95
Exactly 37 seconds after liftoff, a software bug in the inertial reference system led to a critical data conversion error,
96
where a 64-bit floating point number was incorrectly converted to a 16-bit integer.
97
This made the rocket think it was 90 degrees off course, and when it went to correct at high velocity, it went boom.
98
Luckily, there was nobody on board, but in 2010, the Toyota Prius put a bunch of people in danger due to a bug in its anti-lock braking system,
99
which would cause momentary delays in braking under certain conditions, like on icy roads or potholes.
100
There's something wrong with the brakes.
101
The computer created a 0.4 second delay, switching from regenerative braking to friction braking, and this resulted in a recall of 400,000 vehicles,
102
which was a beautiful thing because it meant there weren't as many Prius drivers driving slow in the fast lane.
103
That was a big mistake made by low-level systems engineers, but front-end developers screwed things up too, like the 2020 Citibank bad UI disaster.
104
Citibank was intending to make an interest payment of $8 million, however, due to a poorly designed UI, they accidentally transferred the full loan amount of approximately $900 million.
105
The software had a confusing three-screen process for payments, and the interface made it appear as though checking certain boxes would ensure only interest was paid, but in reality, it did the opposite.
106
Now, after Citibank accidentally paid back this money, they asked the lenders if they could have it back, and they were like, nah, bro.
107
So Citibank took them to court, but the court ruled in favor of the lenders
108
and let them keep the $900 million that Citibank accidentally transferred due to the bad UI.
109
That's pretty bad, but this tier wouldn't be complete if we didn't talk about the Y2K bug.
110
In the early days of programming, no one thought the world would still be around by the year 2000, so they typically used only two digits to represent years.
111
As the year 2000 approached, people realized this and began to panic that computers would interpret 00 as the year 1900 instead of 2000.
112
What's funny about Y2K is that this issue never caused any widespread disasters, but the media hysteria around it led to billions of dollars being spent in preparation for the end of the world.
113
But now it's time to ratchet up the pressure in tier 4, which includes critical bugs that caused widespread damage around the world.
114
Like the Knight Capital Money Burn speedrun, this company used algorithms to perform trades in the stock market.
115
However, the developers accidentally used a variable name linked to an outdated testing algorithm called PowerPeg, which had been inactive since 2003.
116
This algorithm was designed to manipulate virtual markets by buying high and selling low.
117
Now, if you don't know much about investing, usually you want to buy low and then sell high.
118
That's not financial advice though.
119
When they pushed a prod, the algorithm went haywire and started flooding the New York Stock Exchange with incorrect trades.
120
4 million trades in just 45 minutes to be exact.
121
Knight Capital lost $440 million in a single day and wiped out 75% of investors' equity.
122
But a far scarier bug is Heartbleed of 2014, which was a vulnerability in OpenSSL, a library that's supposed to make internet communication secure,
123
which was caused by a simple coding oversight, a missing bounds check in the implementation of the Transport Layer Security, or TSL heartbeat extension.
124
Normally, when a client sends a heartbeat request, it includes a payload and expects the server to reply with the same payload.
125
However, due to improper input validation, an attacker could send a malicious heartbeat request that appeared legitimate, and this allowed attackers to repeatedly request memory contents from the server,
126
potentially gaining access to highly confidential data without any way to be detected.
127
And that's unimaginably bad because two-thirds of the internet servers were vulnerable.
128
Now, we already talked about Toyota's braking problem, but they also implemented an acceleration problem, where your car would magically speed up uncontrollably and try to kill you.
129
It led to 6,200 complaints, 52 injuries, and 89 deaths.
130
This one could have gone in Tier 5, but it was a multitude of issues that caused the problem, not just the software.
131
But the investigation revealed that a software bug in the electronic throttle control system was partly to blame.
132
Apparently, the code had terrible error handling logic and lack redundancy, and the code was structured in a way to allow multiple failure points, which could cascade through the entire system.
133
And that's not good when that software is in control of your throttle.
134
Toyota had to recall 9 million vehicles and pay $1.2 billion in fines and settlements.
135
In the previous tier, Y2K was a bit disappointing, but just a few months ago, CrowdStrike gave us the Y2K we deserved.
136
As a cybersecurity company, they convinced companies to install this thing called the Falcon Sensor, which has kernel-level access to all their employees' machines.
137
Everything was going great until one day, somebody pushed a bad configuration file called Channel File 291 to production.
138
This resulted in millions of Windows machines entering the blue screen of death.
139
Hospitals shut down, flights were canceled, and people nearly starved to death after the Arby's drive-thru went down.
140
It was bad, but not as bad as the Northeastern blackout, which occurred on August 14, 2003, when nearly 50 million people in the United States and Canada lost power.
141
First Energy Corporation had a monitoring system for the power grid, but its error handling code wasn't so good.
142
If multiple alarms were generated in a short period of time, the entire system would enter an unrecoverable state without notifying the operators, and this meant that no new alarms would be shown,
143
and no existing ones be cleared, which meant that it looked like everything was normal to the operators, but in reality, half the damn country didn't have power.
144
Luckily, nobody died, but now our submarine is making a weird cracking noise as we get down to the bottom tier.
145
In 1994, a military helicopter of the Royal Air Force took off in Scotland in foggy conditions.
146
The aircraft has an automatic throttle control that takes inputs from sensors placed around the aircraft.
147
But in these challenging conditions, the system became overloaded and didn't know what to do.
148
When things started getting weird, the pilots tried to regain manual control, but eventually lost total control, and 25 people died in the process.
149
The investigation found that the throttle control software was not adequately tested under these conditions.
150
But perhaps the most famous deadly software bug is the Therac-25 radiation machine.
151
This was a device used to treat cancer patients by providing a therapeutic dose of radiation.
152
Unfortunately, it was yet another device with inadequate air handling, and when it encountered a race condition, it wouldn't just break, but it would deliver the patient with a lethal dose of radiation.
153
And at least three patients died after receiving radiation doses 100 times higher than intended.
154
In addition to the race condition bug, the device also removed mechanical interlocks that provide a physical safeguard from things like this happening, and instead chose to rely entirely on software.
155
And that was a fatal mistake.
156
But usually when software kills people, it has to do with the military-industrial complex.
157
In 1991, the United States was fighting the Gulf War in Iraq, and Saddam launched a Scud missile that should have been easily intercepted by the Patriot missile system.
158
Unfortunately, there was a bug in the system's clock and timing calculations.
159
It had a 24-bit timer that tracked time in tenths of seconds, but after it was in operation for over 100 hours without a reset,
160
the timer overflowed, causing it to report incorrect information about incoming threats, and that incoming Scud missile killed 28 American soldiers.
161
For that issue, you can blame a back-end developer, but the 1988 Aegis Combat System disaster was caused by a front-end developer.
162
One day, it accidentally shot down a civilian plane from Iran with 290 souls on board.
163
The investigation revealed
164
that a lack of user-friendly information on the system's display was one of the key reasons
165
that they misidentified the friendly plane as a threat.
166
There was a timing lag that read to misleading altitude data, which ultimately led to a tragic mistake.
167
One of the biggest military contractors, though, is Boeing, and they make many of the jets we fly on, like the 737 MAX.
168
Thanks to programmers, these modern jets practically fly themselves, but maybe that's not a good thing.
169
These planes were updated with a thing called the Maneuvering Characteristics Augmentation System, or MCAS, which would automatically push the nose down to prevent a stall.
170
There were two angle-of-attack sensors hooked up to the system, but it would initiate the nose-down sequence if only one of them provided weird data.
171
But that was a major oversight in the programming, because if one of the sensors provided faulty data, it would start pushing the nose down.
172
And that's exactly what happened on two tragic flights, Lion Air Flight 610 in 2018 and Ethiopian Airlines Flight 302 in 2019,
173
where 346 passengers and crew lost their lives.
174
Boeing's reputation was permanently bricked after all 737 MAX planes were grounded, and the fix was to simply make sure that both sensors were providing consistent data before pushing the nose down.
175
This final tier was tragic, but on the bright side, good code has saved a lot more lives than the lives lost by bad code.
176
Writing entirely bug-free code is difficult, but remember, there are two ways to write error-free programs.
177
Only the third one works.
178
Thanks for watching, and I will see you in the next one.

Об этом уроке

Вы практикуете английский с "25 crazy software bugs explained" с помощью техники Shadowing — метода, разработанного для подготовки профессиональных переводчиков.

Слушайте каждое предложение, обращайте внимание на ударения и связывание звуков, затем повторяйте вслух уверенно. 15–30 минут ежедневной практики дадут заметные результаты.

Что такое техника Shadowing?

Shadowing — это научно обоснованная техника изучения языка, изначально разработанная для подготовки профессиональных переводчиков и популяризированная полиглотом доктором Александром Аргуэльесом. Метод прост, но эффективен: вы слушаете аудио на английском от носителей языка и немедленно повторяете вслух — как тень, следующая за говорящим с задержкой в 1–2 секунды. В отличие от пассивного прослушивания или грамматических упражнений, Shadowing заставляет мозг и мышцы рта одновременно обрабатывать и воспроизводить реальные речевые паттерны. Исследования показывают, что это значительно улучшает точность произношения, интонацию, ритм, связную речь, понимание на слух и беглость речи — что делает его одним из самых эффективных методов для подготовки к IELTS Speaking и реального общения на английском.

Техника шедоуинга: читать полное пошаговое руководство →