12 ms·
For people finding this thread via web search in the future: screen.studio is macOS screen recording software that checks for updates every five minutes. Someh
by mieko 1y ago
For people finding this thread via web search in the future:
screen.studio is macOS screen recording software that checks for updates every five minutes. Somehow, that alone is NOT the bug described in this post. The /other/ bug described in this blog is: their software also downloaded a 250MB update file every five minutes.
The software developers there consider all of this normal except the actual download, which cost them $8000 in bandwidth fees.
To re-cap:
Screen recording software.
Checks for updates every five (5) minutes. That's 12 times an hour.
I choose software based on how much I trust the judgement of the developers. Please consider if this feels like reasonable judgement to you.
- VWWHFSfQ 1y agoI would be so embarrassed about this bug that I would be terrified to write it up like this. Also admitting that your users were forced to download 10s or 100s of gigabytes of bogus updates nearly continuously. This is the kind of thing that a lot of people would just quietly fix. So kudos (I guess) to blogging about it.
- vrosas 1y agoWhen I built an app that “phones home” regularly, I added the ability for the backend to respond to the client with an override backoff that the client would respect over the default.
- aziaziazi 1y agoCould you expend on what is an "override backoff" ?
- treyd 1y agoPresumably the back end could tell the client not to check again for some amount of time. Sounds similar but different to cache TTLs, as those are passive.
- ses1984 1y agoThe client might have a feature to retry certain failures, and it’s using a particular rate, probably not retrying n times one right after the other in rapid succession. This is called backoff. The server can return an override backoff so the server can tell the client how often or how quickly to retry. It’s nice to have in case some bug causes increased load somewhere, you can flip a value on the server and relieve pressure from the system.
- vrosas 1y agoExactly. Without going too deep into the architecture, the clients are sending data to the backend in real time, but often that data is not actionable during certain periods, so the backend can tell the clients to bundle the data and try again after a certain amount of time, or just discard the data it's currently holding and try again later (i.e. in 5/10/n seconds)
- SnorkelTan 1y agoWhy not just use http retry-after? then you can use middleware/proxy to control this behavior. Downside here is that system operation becomes more opauqe and fragmented across systems.
- vrosas 1y agoBecause the client in this case is not a browser.
- nyarlathotep_ 1y agoWish people would actually do things like this more often. Plenty of things (like playstation's telemetry endpoint, for one of many examples) just continually phones home if it can't connect. The few hours a month of playstation uptime shows 20K dns lookups for the telemetry domain alone.
- gblargg 1y agoSeems like the proper fix would have been to remove the file from the server when they realized the increased traffic. Then clients would just fail to check the update each time and not tie up bandwidth.
- silverwind 1y agoThere is a standard HTTP header for this: Retry-After.
- ryandrake 1y agoYea, it seems like the wrong lesson was learned here: It should have been "Don't abuse your users' computers," but instead it was, "When you abuse your users' computers, make sure it doesn't cost the company anything."
- infogulch 1y agoThat's a good summary and explains many ills in the software engineering industry.
- benwilber0 1y ago> their software also downloaded a 250MB update file every five minutes How on earth is a screen recording app 250 megabytes
- lawgimenez 1y agoI don’t use their software but if someone has they should be able to decompile it.
- iends 1y agoIt's an electron app.
- mobilemidget 1y agoOr.. Why on earth you need to check for updates 288x per day. It sounds and seems more like 'usage monitoring' rather than being sure that all users have the most recent bug fixes installed. What's wrong with checking for updates upon start once (and cache per day). What critical bugs or fixes could have been issued that warrant 288 update checks.
- partdavid 1y agoIt sounds right, and this is the kind of thing I'd expect if developers are baking configuration into their app distribution. Like, you'd want usage rules or tracking plugins to be timely, and they didn't figure out how to check and distribute configurations in that way without a new app build.
- hulitu 1y ago> they didn't figure out how to check and distribute configurations in that way without a new app build. Any effort to use their brain shall be drastically punished. /s
- f1shy 1y agoWhat's wrong with checking for updates upon start once (and cache per day) For me that would also be wrong, if I cannot disable it in the configuration. I do bot want to extend startup time.
- senordevnyc 1y ago[flagged]
- KronisLV 1y ago> To re-cap: Screen recording software. Checks for updates every five (5) minutes. That's 12 times an hour. The tone might be somewhat charged, but this seems like a fair criticism. I can’t imagine many pieces of software that would need to check for updates quite that often. Once a day seems more than enough, outside of the possibility of some critical, all consuming RCE. Or maybe once an hour, if you want to be on the safe side. I think a lot of people are upset with software that they run on their machines doing things that aren’t sensible. For example, if I wrote a program that allows you to pick files to process (maybe some front end for ffmpeg or something like that) and decided to keep an index of your entire file system and rebuild it frequently just to add faster search functionality, many people would find that to be wasteful both in regards to CPU, RAM and I/O, alongside privacy/security, although others might not care or even know why their system is suddenly slow.
- mieko 1y agoFor contrast: Chrome, a piece of software which has a huge amount of attackable surface area, and lives in a spot with insane stakes if a vulnerability is found, checks for updates every five hours, last I read.
- turtlebits 1y agoNoone is commenting on the actual bug. The fact that it auto downloads 250mb updates is user-hostile. On top of that, checking every 5 minutes? What if I'm on a mobile connection? Why not just follow every Mac app under the sun and prompt if there's an update when the app is launched and download only if the user accepts?
- f1shy 1y agoI think the critique here is not directed to 1 individual, the guy who actually wrotw the code. That would be ok, can happen. Here we are talking about the most valued company in the world, which hopefully has many architects, designers and literally an army of testers… and then make such a brutal error.
- zahlman 1y agoNot everyone even has an Internet connection that can reliably download 250MB in 5 minutes. Yes, even in metropolitan areas in developed countries in 2025.
- f1shy 1y agoGermany?
- zahlman 1y agoCanada. But yes, I've heard the stories about Germany, and Australia too. In point of fact, I can fairly reliably download at that rate (for example I can usually watch streaming 1080p video with only occasional interruptions). The best case has been over 20Mbit/s. (This might also be partly due to my wifi; even with a "high gain" dongle I suspect the building construction, physical location of computer vs router etc. causes issues.)
- Hikikomori 1y agoEven doable on very long range ADSL, guess there are still some dialup users.
- zahlman 1y agoNot dialup. Just bad last-mile wiring, as far as I can tell. Apparently such service is still somehow available; I found https://www.dialup4less.com https://www.dialup4less.com with a web search. Sounds more like a novelty at this point. But "real" internet service still just doesn't work as well as it's supposed to in some places.
- mlyle 1y agoThat's 6.5 megabits/second, plus overhead. Many DSL circuits exceed this, but not all.
- Retric 1y agoMost DSL I’ve seen has been way slower than 6.5 megabits/s. If you’re that close to infrastructure you can likely get cable etc. 1.5megabits/s is the still common, but Starlink is taking over.
- Tade0 1y agoSeveral months ago I was dealing with huge audio interruption issues - typical sign of some other, blocking, high-priority process taking too long. Turns out Adobe's update service on Windows reads(and I guess also writes) about 130MB of data from disk every few seconds. My disk was 90%+ full, so the usual slowdown related to this was occurring, slowing disk I/O to around 80MB/s. Disabled the service and the issues disappeared. I bought a new laptop since, but the whole thing struck me as such an unnecessary thing to do. I mean, why was that service reading/writing so much?
- bredren 1y agoLittle Snitch catches these update request checks and I realize now that it should have an additional rule meta which is *how often* this endpoint request should be allowed (LS should allow throttling not just yes / no)
- tough 1y agomurus+snail?
- ljm 1y ago$8000 for 2 petabytes of traffic is pretty cheap for them also. There are plenty of shitty ISPs out there who would charge $$ per gigabyte after you hit a relatively small monthly cap. Even worse if you're using a mobile hotspot. I would be mortified if my bug cost someone a few hundred bucks in overages overnight.
- aidenn0 1y agoIt got one of their customers booted off of their ISP; they did cover that person's overage costs though (and hopefully that person could get their account back).
- outsidein 1y agoMicrosoft InTune WUDO has a similar bug costing my department 40000 € internal charging per month for firewall log traffic of blocked tcp 7680 requests. 86000 requests per day per client, 160 million per day total. MS confirmed the bug but did nothing to fix it.
- skirge 1y agohow? Do you investigate each blocked packet as separate alert?
- outsidein 1y agoYes, all packets get logged (metadata only). Otherwise we wouldn’t know there is an issue. Those packets consume bandwidth and device utilization, too but this is flat fee, whereas log traffic is measured per GB so we investigated where an unexpected growth came from.
- hulitu 1y ago> MS confirmed the bug but did nothing to fix it. They are building features right now. There are a lot of bugs which Microsoft will never fix, or it fixes them after years. (Double click registered on mouse single clicks, clicking "x" to close the window, closes also the window underneat, GUI elements rendered as black due to monitor not recognized etc).
- coldcache 1y agoObviously five minutes is unnecessarily frequent, but one network request every five minutes doesn't sound that bad to me. Even if every app running on my computer did that, I'm not sure I'd notice.
- hulitu 1y ago> but one network request every five minutes doesn't sound that bad to me Even if it is made to CIA/GRU/chinese state security ? /s
- alpaca128 1y agoPeople complaining about 5 minute update checks hopefully don't use Windows 10/11. A while ago I did some rough calculations with numbers Microsoft used to brag about their telemetry, and it came out to around 10+ datapoints collected per minute. But probably sent in a lower frequency. I also remember them bragging about how many million seconds Windows 10 users used Edge and how many pictures they viewed in the Photo app. I regret not having saved that article back then as it seems they realized how bad that looks and deleted it.
- homebrewer 1y agoIt's probably their way of tracking active users without telling you so, so it makes a lot of sense to "check for updates" as frequently as possible.
- crazygringo 1y agoEvery 5 minutes is too often yes, but it hardly matters for a tiny HTTP request that barely has a body. So yes it should only be once a day (and staggered), but on the other hand it's a pretty low-priority issue in the grand scheme of things. Much more importantly, it should ask before downloading rather than auto-download. Automatic downloads are the bane of video calls...
- sandworm101 1y agoThats only half as bad as a certain company that had all thier users download an unwanted OS upgrade on the theory that one day they might click the install button by accident. "We will stop filling your drives with unwanted windows 14 update files to you once you agree the windows 12 and 13 eulas and promise to never ever disconnect from the internet again."
- esalman 1y ago* 12 times per hour per user.
- therealpygon 1y agoI don’t know this software, but my sense is that this would be exactly the type of desired functionally in order to bypass rejected user metric sharing by parsing update request metrics, but maybe you are right and the Developers really do believe you can’t go more than 5 minutes on an out-of-date version…
- londons_explore 1y agoWell designed software does not poll for anything - everything is event based. In this case, that means an update should have been sent by some kind of web socket or other notification technology. Today no OS or software that I'm aware of does that.
- treve 1y agoSo your conclusion is all software that polls is badly designed? Keeping a TCP socket open is not free and not really desirable.
- londons_explore 1y agoMost platforms offer other notification channels - ie. Web push. Those truly are free.
- Chaosvex 1y agoNo, those are abstraction over a TCP socket and introduce more complexity than you'd need for something like this. There's nothing wrong with occasionally polling for updates.
- londons_explore 1y agoWeb push, FCM, APNS, etc are free because they only have a single systemwide TCP channel open - and that channel is already open whether or not your app chooses to use it. Your app can also be ready to receive notifications even when the app isn't running - using zero RAM. Inetd on Linux allows similar stuff (although no ability to handle ip changes or traverse NAT makes it fairly useless in the consumer world). This stuff is important because polling dominates power use when idle - especially network polling which generally requires hundreds of milliseconds of system awakeness to handle tens of network packet arrivals simply for a basic http request. Did you know, a typical android phone, if all polling is disabled, has a battery life of 45 days?
- gus_massa 1y agoFrom the article: > Add special signals you can change on your server, which the app will understand, such as a forced update that will install without asking the user. I don't like that part neither.
- deleted 1y ago[deleted]