4 ms·
How? 1. Lack of automated unit tests covering the code in question. 2. Lack of automated functional tests running through scenarios of setting up an encrypted
by cliffy 9y ago
How?
1. Lack of automated unit tests covering the code in question.
2. Lack of automated functional tests running through scenarios of setting up an encrypted volume with or without a hint.
3. Lack of strict review process for the disk utility's codebase.
This assumes automated tests are also peer-reviewed.
1 - 3 won't guarantee a bug-free project, but I doubt this bug would've made it into production.
- Xynap 9y agoCompletely agree that adequate automated testing would have caught this but still ... You'd think the developer/QA that worked on that particular feature would have manually tested it at least once.
- jaclaz 9y ago>You'd think the developer/QA that worked on that particular feature would have manually tested it at least once. Or anyone else, it is seemingly not a hidden, elusive bug that can only be caught when a number of particular conditions concurrently happen. According to Matheus Mariano (that seemingly was the first to find it and report to Apple): https://news.ycombinator.com/item?id=15408258 https://news.ycombinator.com/item?id=15408258 https://medium.com/@matheusmariano/new-macos-high-sierra-vulnerability-exposes-the-password-of-an-encrypted-apfs-container-b4f2f5326e79 https://medium.com/@matheusmariano/new-macos-high-sierra-vul... The only needed condition is that the Mac has a SSD, and in his words: "I really don’t know how this went unnoticed by Apple (and anyone else). "
- revelation 9y ago1-2 kind of require having a proper UI testing framework in place. And when you have that for your platform that you want people to develop for, surely you would release it. I haven't seen any of that.