"Some birds aren't meant to be caged, their feathers are just too bright"- Morgan Freeman, Shawshank Redemption. This blog is from one such bird who couldn't be caged by organizations who mandate scripted software testing. Pradeep Soundararajan welcomes you to this blog and wishes you a good time here and even otherwise.

Friday, May 10, 2013

Emailing skills and its power to influence for software testers (no, just me)

No matter how much you probe people who are successful they won't tell you some secrets - not because they don't want to tell you but because they don't all the time recognize the smallest most ignored thing they did great were the secrets.

To me, when people talk about testing skills, they often leave out writing skill. They don't recognize it. Even if they do - there are several forms and forums where testers write and their writing has to vary accordingly to help them influence the project and decisions. Most of us know about bug reporting writing. I don't know of many people who give importance to emailing skill but I attribute emailing skills to be a major contributor to my success so far. In Moolya, we have emailing skill training to everybody and we constantly review good bad and ugly emails to help our folks be better than some of us. At all levels, we keep reporting bad practices on email. Parimala has even used some of my emails to show bad examples in signature section in emails and why it matters to have a signature that helps people reach you when needed.

I was looking into some emails and found a consulting assignment email that I had sent to a client I worked for in 2009 and thought it would be a good idea to put it up for the world. When Parimala reviewed the emails she thought it was brilliant and finally has something to show to testers in Moolya from on the good example side. I asked if I should publish this on my blog and she instantly liked the idea. So, here it goes:

The way I email daily updates is, I go to the previous sent email and send it as a reply to all adding the current day's update. So, if you were to receive a day 12 report, scrolling down, you will see all other day updates. I don't want to give extra gyaan but whatever you can take away from the below email, take it. 

Product information, people name, customer names and other confidential information have been changed to not breach the NDA I signed with them. 


On Thu, Oct 7, 2010 at 11:18 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:

Day 14:

         I couldn't sleep yesterday night after finding those issues. I was excited and continued testing till about 2 AM from the guest house.
         Its pretty exciting to be finding these issues and hoping its of value to you.
         I discovered yesterday that Firefox, the application we allow itself is a culprit that can help users bypass the security. Just launch firefox, type c:\ in the address bar, enter, you have access. No policy blocks.
         The other important issue that I have reported includes user being able to change the settings of McAfee virus scan itself. I was able to exclude my desktop to be scanned, downloaded a test virus and it resided without being cleaned or deleted. I could initiate a scan of registry entries, folders.
         By this, I have kind of violated almost all policies set.

Tomorrow,

         Will be end of the contract day
         I am hoping to report a few more issues that I have been investigating today.
         I shall publish to you my test strategy, test coverage, analysis, suggestions, experience report. As this would take some time to do it, I may send this early next week.
Thanks,

-- Pradeep Soundararajan

On Wed, Oct 6, 2010 at 11:46 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Day 13
         Continuing the investigations on Deskpro, I figured out more vulnerability today. These are even more serious ones than yesterday's reports.
         I have access to all drives now C:\ Q:\ F:\ this time not over command prompt but through 7Zip
         I could write into these drives. I have left a file C:\TRU\ called pradeephackedthis.txt
         I could copy all visible data to me to my local folders
         I could view individual user accounts, settings, what they have on their desktop, what they have browsed, what cookies are set on their system. 
         I can go write a cookie into their system and steal all data without their knowledge.
         I could install applications into their login. For instance, I put a zip file into Startup folder of users that when opened contains about 50 MB of data in it. There is a way to deny users with space.
         Even if a user discovers it by accident, rest is going to be excitement for him and disappointment for us.
         I could initiate an install of applications with no restrictions from the GUI itself. In fact I did end up reinstalling Tomcat.
         I feel like a super admin without needing the password or login for it.
         The thing to note is: The policy did block me but not all times.
         There are other basic functional issues as well that will be reported.
         These issues will be reported in Jira tomorrow with necessary screenshots and further investigation
Thanks,

-- Pradeep Soundararajan

On Tue, Oct 5, 2010 at 10:43 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Day 12:
         I continued testing on Deskpro focusing on functional & security issues
         Users email ids, login ids can be accessed: this is privacy policy violations. Customers may sue for privacy violation.
         Lots of open source software for windows desktop are bundled in zip file, when downloaded, all exe run inside zip despite policy restrictions
         Command prompt clones run and allow access to C:\ drive
         I could write files in C:\Windows & C:\Program Files & System32 folders
         I could see the admin policy settings
         Apart from these, I have installed software in C:\Program Files which reflects in not just my account but all users connecting to SRIVER11.
         So, if 50 users are installing 10 applications, every user may see 500 applications installed in his login
Tomorrow:
         Continue testing Deskpro / Mutro
         Investigate and report issues found today in Jira
Thanks,

-- Pradeep Soundararajan


On Mon, Oct 4, 2010 at 11:05 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Greetings! Hope you had a great weekend and having a good week ahead.

Day 11:
         The netbook I had where I was able to delete the Bravo folder had some issues even after reflashing it. So, about half of the day was spent on waiting that I'd get the netbook in the next 15 minutes. My mistake, should have gone immediately to Deskpro from nLive.
         Post afternoon, I started testing Deskpro from nLive and found some critical issues related to privacy of registered users. I could get access to all thousands of registered users of entire network and their email ids.
         Beyond that, I could install applications and it gets reflected in other people's account as I was able to install it in the C:\Program Files of SRIVER11. So, when logged in with admin privileges from R account, he could get the applications I have installed. This is again, in my opinion, something critical.
         Apart from these I have reported a few functional and Usability related issues.
         I am hoping to get the netbook again tomorrow, even otherwise I have Deskpro through nLive.
         As a side note, I had some amazing discussion with Architect & insights about Mutro, Deskpro & iDrive. 
Thanks,

-- Pradeep Soundararajan

On Fri, Oct 1, 2010 at 5:17 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Day 9:

         QA Review meeting: Thank you for briefing me on what you want me to focus on going forward. This was important for me to be of value to you.
         Focus is on functional problems for 2.0 October release.
         Prior to this & post the meeting, I have reported the functional issues I could find on Mutro

Day 10:

         Testing for functional problems and user based scenario problems on Mutro + iDrive
         Reported a couple of issues on functionality.
         Reported a blocked where after successfully launching iDrive I could move the /home/Bravo folder to trash, making all applications in Mutro to fail.
         I have reported about 19 issues over the last two days and most of them being functionality related.
Week 3:

         Focus on Functionality of iDrive, Mutro and Deskpro
         Find as many important problems as possible and report all of them
         Touch base with Architect and team on a constant basis.

Thanks,

On Wed, Sep 29, 2010 at 7:05 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Today:

         Worked entirely on netbook
         Got the test login from Admin Personnel for Server 2008 and explored on it for an hour.
         Covered areas: toolbar options, zones, user scenarios
         Found issues related to Usability, Functionality & User expectation violation
         Reported most of the issues confirmed on Jira
         Rest of the issues that need investigation shall be reported tomorrow.

Tomorrow:

         Focus of testing Mutro shall continue
         Have asked Admin Personnel for a few policy changes that would bring Deskpro closer to what the users might be using it in future to continue my tests on it.
         QA Progress meeting with PM, TL, Architect & Admin Personnel
         Shall be leaving office in the afternoon
Thanks,

-- Pradeep Soundararajan

Resending the same with updated Subject line (Day 7 instead of Day 6 as per previous email). Sorry.

Hi All,

What I loved:
         I loved the idea of showing what's happening within each zone in the preview mode. For instance I initiated Deskpro and before it completely launched I opened a new zone and went to My Zones, I could see what was opening / happening inside Deskpro in the thumbnail view. 
         That is a real cool feature to provide to the user especially when you allow them to preview multiple zones.
Today:
         I spent time investigating some of the issues I had found yesterday
         I did get Netbook and my testing focus is Mutro / Deskpro on Netbook
         I reported issues found on Mutro (Netbook) to Jira
         Dev 2 & I had a bug triage meeting scheduled and this shall be a daily activity from today. We discussed and scrubbed the issues reported. This activity is definitely helpful.
         I also did test Welcome Bravo on Deskpro launched from nLive and shall investigate the same on Netbook before logging it in Jira.
         Some more security issues to be reported for Infra team
         Had a lunch meeting with Admin Personnel on Infrastructure related issues. I learnt that migration will happen to Windows Server 2008. Admin Personnel communicated that he would give me a test login that should help me identify risks and re-test security for Server 2008.
Tomorrow:
         Wider & Deeper coverage of Mutro on Netbook with focus towards any kind of issues that might impact the business or user experience.
Thanks,

-- Pradeep Soundararajan

On Mon, Sep 27, 2010 at 7:34 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Today:

         As said in Day5 report, I started with reporting the issues I had found on Friday which consumed 1/3rd of the time in day.
         The netbook had some issues and later was being fixed by Dev 2 so I still haven't started testing on it but the good thing is I didn't keep mum.
         I continued testing Deskpro from my own laptop this time.
         I continued performing security & functional tests and found a bunch of issues again which would go to Jira soon.

Strategy suggestion:

         Today's testing revealed some more security issues related to Deskpro. I could traverse to get through the Scheduled tasks set on Sriver 11 and could set tasks of my own. For instance, I could see "Orphan Port Delete" scheduled task and its frequency.
         I could get an option to look at the Windows Terminal Network which is connected to the Sriver11 although I couldn't see beyond Sriver11 on it.
         I could access Microsoft Outlook on Sriver11, set accounts on it or send and recieve emails.

         I feel, I have found enough security issues to help the teams rethink about the policies, firewall and system settings.
         Otherwise it would be same kind of information over loaded.
         I think I should focus on other quality criteria henceforth - Functionality & Usability with less focus on Security.
         That way, I can be of more value to you.
         I am open to suggestions from you though.
Tomorrow:

         Report issues found today with screenshots
         Should be getting the netbook and testing Mutro & Deskpro from that.
         Test for Usability & Functionality
Thanks,

On Mon, Sep 27, 2010 at 9:54 AM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Friday:
         The report I had to send on Friday evening is what I am sending now.
Progress:

         Was covering User Experience Testing of Mutro on Cloudbox
         Found issues related to User Experience & Flows that users are more likely to hit upon
         Focus then shifted to Penetration testing on Deskpro
         Some of the cool security issues were uncovered such as there are competing anti spyware programs that can be installed which gives us access to kill McAfee and take much more control over the system.
         I could uninstall Winamp, see the process running on SRIVER11, kill some of them, run a Spyware scan and so forth.
         Rest assured, these are going to Jira today.
Today,
         I shall be reporting the issues found on Friday into Jira
         I should start testing Mutro & Deskpro from Netbook
         Most testing from now on would be from the Netbook
         Focus remains on User Experience & Security
Thanks,

-- Pradeep Soundararajan

On Thu, Sep 23, 2010 at 9:45 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All, 

Greetings!

Today:
         Today started off with a meeting with Tester where he showed me the testing he and PM had done on Mutro which gave rise to a few more ideas and scenarios for me.
         I continued to test on Cloud PC for a while tell Dev 2 came in and we decided to move to the latest version ( I was testing on RC3 )
         Post TL and Dev 2 meeting we decided that the issues I report would be considered for fixing post the Customer X/CUSTOMER Y release.
         The upgrade on cloud PC had some issues so instead of watching it get upgraded, I started picking up the issues I found yesterday, investigated and reported them.
         I was on the catch up call with CEO, TL and Dev 2.
         CEO set the goal for Black Box User Perspective Testing on Mutro
         I also continue to add on to my list of the kinds of test coverage we need to be able to achieve a wider and deeper testing.
         At about 6 PM my laptop broke (physically), I have now had a temporary fix to it which can help me continue tomorrow without any significant issues. [ pretty childish? :) ]
Tomorrow:
         I start testing Mutro from Tablet PC than Cloudbox
         I shall continue to report issues as and when I find.
         I shall log the security issues under the about to be created Security section in Jira
Help & Support:
         Joining you people mid way through your journey of Cloudbox and new customer requests, I am not the best person to be able to judge the priority of the bug, so I request the help of respective module leads to take a look at the bug reports at the end of the day and change its priority accordingly.
         I was under the impression that I was reporting the severity of the problem and not the priority because it is only you who understand the business layer who can set it.
         So, I would continue to report issues with my limited judgement and I shall rely on module leads to change the severity and priority for the issues I report.
         From my end, I shall ensure I provide as much evidence as possible to the bugs I report. 
Thanks for your time and patience that I value,

-- Pradeep Soundararajan
On Wed, Sep 22, 2010 at 7:45 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Greetings!
         I got access to Mutro today
         Half of my time was spent on learning & exploring Mutro & Deskpro through Mutro ( which is towards release 2.0, correct me if I am wrong )
Today

         I reported a few issues in Jira & shall start reporting issues to respective projects henceforth.
         I found issues that breach the security policies which I shall be reporting tomorrow morning into Jira as I am on the final leg of investigation. Issues such as Bravocentre.exe and Welcome_tillSep08.exe can be copied and transported over internet and disassembled.
         TL brought to my attention of a release being made to Customer X / CUSTOMER Y next week and set a goal to find issues of Mutro from users perspective of usage that can be passed to Dev 2 ( did I spell it wrong? )
         I have attached the issues I found so far as a text file to this email ( Not to worry - these will be going to Jira ) and I am set to uncover more such issues tomorrow. 
         As a side note: I am dealing with opportunity cost of finding issues versus reporting them. One takes away time from another.
         I am making a list of things to be covered for testing of Mutro as and when I use it.
Tomorrow's plan:
         Continue testing Mutro and Deskpro for Functional, Usability & Security issues
         Report bugs in Jira
         Sit with Dev 2 once he is back and unlearn things I might have incorrectly learnt about Mutro
Thanks,

-- Pradeep Soundararajan


On Tue, Sep 21, 2010 at 8:03 PM, Pradeep Soundararajan <PSoundararajan@Bravo.com> wrote:
Hi All,

Greetings!

         Mixed day ( No power for first 2 hours and then intermittent day coupled with some good issues )
         You would discover that I am emailing from Bravo id, so I got it and Jira access too.
         I am reporting issues in Jira under QA & Testing
Today:
         Used the no electricity time to interact with Admin Personnel and understand the infrastructure and security of the Bravo cloud a little deeper
         Used the tea break to discuss with Marketing & Sales team about existing issues.
         I have planned to do a paired testing approach with Marketing and Admin Personnel individually to be able to identify more issues.
         Post TL's meeting with CEO, I learnt the focus doesn't need to be on Live as of now and is on Cloudbox & Deskpro or 2.0 release if I may say so.
         Post discussion with Marketing, I identified I would also need a Data card connection to be able to test from a typical wireless access modelling real user scenario.
         TL is going to help me get a Cloudbox tomorrow and that would also be a part of my testing from tomorrow.
         Read the Bravo Blog
Issues:

         I have reported about 10 issues in Jira as of today coupled with testing performed.
         Some issues from yesterday's investigation and some with todays. I am covering security and purpose hand in hand while learning more about the product.
Tomorrow:

         Waiting to get my hands on the Cloudbox & continue to increase the test coverage
Thanks for your time so far,

-- Pradeep Soundararajan

Tuesday, April 30, 2013

The ISTQB scam and why you should sign Keith Klain's petition

If you know what I am talking about - go here right away and sign the petition. If you do not, read this:

If you are my blog reader, you would know why ISTQB is a shame, a scam and faking its agenda. Despite the awesome challenge put up, its promoters are not revealing publicly how the profit is used (considering they claim it is not for profit) 

When Keith Klain, Michael Bolton and others on twitter challenged Rex Black to reveal the details - there was a response quoting NDA and other stuff which keeps them in hiding. I strongly believe this is not helping the testing community. It is actually damaging. 

Let me detail how ISTQB is a shame, scam and faking its agenda. 

Scam part

The certification by itself is pretty cheap - giving it a nice disguise that they make less money. However, there are these training for the cheap certification that is really expensive. I have a pre final year college graduate who wanted to try her luck, try ISTQB, cleared it and does not have a clue on how to test email me and ask what can she do about testing?

The ISTQB charges a fee to these training institutes for allowing them to use their name. Some of its promoters have their own companies that do ISTQB training. So, ISTQB as an organization was built to show they are not for profit but those who say it is not for profit - use their own company names to make the profit out of ISTQB. 

Shame part 

All parts are shame, I am wondering where to start. The biggest according to me is - it has some smart people working for them and they are wasting their time by blinding them from information that ISTQB has not really advanced how people test over time. Sometimes, money blinds and other times fame.

About 7 years ago, I was trying to apply to Accenture, online. I filled in a bunch of details and then before uploading my profile after selecting software testing category, I found that it asked me to select the certification I have. I could not even apply to their company because I did not have a certification.

The bigger shame is - when I talked about this - the ISTQB fellas said, "We don't ask them to do it but it is not our business to get them to change it". Wow! This is awesome. So, if someone is screwing up the world with your already screwed up certification, you don't say anything about it. So, you don't really care for testers skills. How can this not be a non profit?


Faking the agenda part

Time and again, the world has understood a 40 question cannot determine knowledge or skills yet they have not changed how they test testers. The reason is simple, the bad is easily scale-able. The good is not. It at least requires a lot of skilled effort. 

Also, the marketing and advertising they put up in magazines, conferences and other places (I haven't checked any bill boards) is misleading. It ranges from ROI on this certification to how better testers can be after this. 

I have been employed in services companies that have asked me to take ISTQB and my appraisal would depend on that. So, people are forced to take it up. Most of my colleagues took it up for their appraisals and that is how they drive it. Are we creating passion? Are we creating a better community?

There is no advancement. Companies test the way they have been doing for a long time. Most companies that have adopted ISTQB are the ones breeding testing that has not changed. 

 If this is enough: go to the petition right now and show your courage to stand up against the scam! If you are not courageous, you will someday be inspired by the context driven community.

Thankfully, Keith asks questions whose answers reveal evidence of what I have said above from my experience!

Sign the petition Sign the petition Sign the petition Sign the petition Sign the petition Sign the petition Sign the petition

Saturday, March 30, 2013

A culture bug that impacts software testers in India


We all know the way we have been brought up has had a huge influence on how we see things. Some of us have benefited and others have not. Most of us have a mixed bag.

A culture bug in India

Each of our countries has a culture that has rubbed off on how we are brought up. Indian culture teaches respect. If someone is elder, no matter how stupid they are, kids are taught to respect them because they are ELDER and they are always correct. There could be a notion that elder means wiser but sadly, that is not true in many cases. If someone is a senior at work, no matter how much they are sinking the boat, we are taught to respect them because they are SENIOR and they are always correct. If the teacher at school did beat us up for not doing home work, we were taught to not be worried about being hit but instead feel guilty for not doing home work because they are TEACHER and they are always correct. At least till the previous generation, women were mostly considered to be electricity-less Roti makers by most men and also were considered less intellectually superior. So, women had to offer a lot of respect to men irrespective of how screwed up the men were. That was the case because they are MEN and they are always correct.

Slowly, over generations, the people who are offered respect have learnt to misuse it. So, there are plenty of organizations who say to their testers, "How dare you speak like that to the CEO?" and "I am your reporting manager and I can screw your career", "If you don't do things to please me, I am going to impact your hike and promotion", "How can you go to my manager and talk about me?"

Those who offer respect also have a tendency to think that they are less superior or less powerful and this makes them act like a slave, not escalate issues, not inform the decision makers the truth and allow someone to screw up the entire company and its culture. It is simple, when the boat sinks, move to another boat. This is why hiring has become a challenge for organizations who want to grow. They got to be careful that people don't see the boat as "yet another boat to sink".

Similar culture bug in other countries

Other countries have their own version of this problem. For instance Malcom Gladwell, who happens to cover great stories, exposed how culture impacts plane crashes. In the book Outliers, Malcom covered The Ethnic Theory of Plane Crashes. If you were to read that piece of brilliance of thinking and writing, you would know Korean Airways had the highest number of crashes in 70's and 80's because their culture was in such a way that the co-pilot did not oppose the captain because he was a SENIOR and by virtue, a senior is always correct. The story gets a twist when the culture is hacked and people are re-trained on how to and not to respect the senior. As of today, Korean airways is one of the safest, at least, as per Wikipedia, there is no report of plane crash in Korean Airways since 2000.

If that happened in Korea, it must have also happened in India. I was trying to see if any plane crash in India had a similar pattern. The most recent plane crash in India was the one that happened in Mangalore where 152 passengers and crew were killed in Air India Express Flight 812 crash. You should read this part and figure out that the co-pilot warned the commander but the Serbian commander didn't heed to the warning because the commander was the SENIOR. Without guess, thousands of air travellers might have been killed by the human bug of culture so far. The West can't be different than east as I believe, the West houses humans as the East do. There could be a different culture bug there than in here.

When is it OKAY to give bad news information that hurts people?

In Moolya, there is this wonderful young tester by name Manju. Her passion to work, dedication and commitment is unquestionable. She is highly trust worthy. Our customer seconds my understanding of Manju and has high respect for her commitment and trusts her. However, there is one aspect of Manju that is a side effect of all the good qualities she has - which is - she does not say anything that hurts anybody.

The nature of the job as a tester, is to find information and present information. Not all information is welcomed.  Some information could violate assumptions or shatter the possibility of a goal being accomplished and this can definitely hurt. It is the information that does hurt, not the human who hurts another. So, stop confusing yourselves that testers find bugs in people or their work.

With Manju, I have been repeatedly trying to hack into her thought process and help her learn that it is absolutely okay to speak in ways that may hurt people if it is helping the larger objective of why she we was hired for that project. 

In my most recent conversation with Manju, I gave her an analogy, "I am the captain of a ship you and I are travelling. If someone is hammering the ship to make a hole so that water comes in and the ship sinks, would you inform me about it?" and without giving her time to answer, I continued, "You should! Otherwise we all sink. If you do escalate things to me, I may throw the person out of the boat but that is because I am the captain and I want travelers like you to feel safe on this boat. It is a captain's duty to do so and it is your duty to keep the captain informed about it". I pray she gets it and I shall hack in every time into her 20 years of education that says, "Don't say things that may hurt people". I have suggested her to read Malcom Gladwell's coverage on airplane crashes and the culture bug. I am sure she would understand that saving thousands of people is more important than hurting the captain with bad news.

There is so much of value she has added to the project that she is now leading the delivery for the project and this came to her because of her good work. It would be more valuable if she were to be telling things the way they are without being worried if it would hurt somebody or not because, at times not telling such things will sink the boat she is in, irrespective of how much she cares for the safety of the boat.

The Indian Military and how they don't confuse the reverent culture

I was talking to Paul Carvalho over Skype yesterday and he was narrating a story about how he established his position as a test consultant a couple of years back. He had to oppose certain decisions taken prior to his appointment. He had to help his company recognize that they actually hired him to solve the problem. I told Paul that I would wish to hack into the culture of some Moolya testers and help them do what he appears to be doing. He came up with this beautiful thing asking, "Maybe you may want to explore how better you can use your own culture to teach them than bringing in examples from other cultures"

James Bach spoke about how Indian testers can benefit from their own culture in his talk at Test-Ed 2012. He also delivered great reminders to Indian testers on how they seem to have forgotten the wealth of information that exists about testing in India from its history and mythology. He referred to the Indian culture as a reverent culture and said there is power in it.

While we should learn a lot of good thinking skills from Indian culture and history we should not misunderstand reverence to offering respect at the cost of the purpose. Paul's question triggered a thought process in me that he found it profound. Here is how it goes:

I said to Paul that I am not bringing examples from other culture to Moolya testers to change their culture but to help them remind how the Indian Military forces work despite our reverent culture. Their job is to be prepared, remove obstacles and keep progressing.

This learning comes from a conversation I had with my cousin brother who serves the army as a Colonel who fought the Kargil War in 1999.  In 2002, then a Major and Joint Commanding Officer at the Jawan Training center in Secunderabad, I had an opportunity to visit him and see the rigor that our Jawans go through to get trained to fight war. The documented rule in the military says, "If a SENIOR is a coward or creates panic at war zone, runs away at the hands of enemy and fails to fight the enemy, he can be killed by any officer who notices this, irrespective of their rank". If they fail to kill such a person, the panic or cowardliness could spread and we shall end up losing the war. Acting upon information is leadership. You don't need a designation as a Leader to be a leader.

The non obvious thing about software business

In the software field, it is less obvious that many families are dependent on the work we do. For instance, Manju works for our customer who is a start-up and boot strapped. The founders are pumping in all of their money to get their business going. They have families and need to earn bread for their family. They also need to pay their employees and vendors on time. They are more or less in a war like situation. They need to know the obstacles before they have to encounter it. They can't see obstacles and they have to rely on their people to do so. The more their people understand this, the better it is for them. If they happen to lose business, that would spiral on their employees and vendors like Moolya.

Well, it is not always that somebody was intentionally hammering to sink the boat. Software is so complex that at times people may remove a nut to fix something else and that may have caused water to leak in. If it is escalated early, the captains have time to fix it. Otherwise, they need to work on Plan B of getting everybody out of the boat, safely. That's not what you should make your captains do.

Recognizing & fixing the bug

For someone fresh out of college and in the first job, how much would they be able to recognize that a leak in the dam can cause the entire dam to break? With a boat, it is obvious, maybe. In business, it is not obvious. Even to those who are running the business. The young folks need to be trained – to recognize leaks and to escalate or fix it.

It is not easy. 20+ years someone has lived a life in a specific way and for me to win their trust to hack their culture looks like a thing beyond human capability. Interestingly, I just can't tell people like Manju to speak up and assume my job is over. I have to create an environment where people who speak up are protected, people who speak up are respected, and people who speak up understand the purpose.

Informing the purpose, reminding them, demonstrating their stake and helping them understand the purpose is my way of how this culture bug can be fixed. You can't be a doctor and say, "I hate seeing blood". You can't be a tester and say, "What if this hurts somebody?” Note that, please, I beg you to be careful - testing does not mean to find bugs in people nor their work. It is about finding and presenting information. The information can offend some people because they may have had an assumption that is violated with it or were in fantasy and you brought them to reality. That is why they hired you. Even if they don’t recognize, you have to.

While getting this reviewed, Paul Carvalho, reminded me of Virginia Satir interaction model that he learned from Jerry Weinberg. Then I happen to read this beautiful piece from Dale Emery about his experience with Virginia Satir Interaction Model and I know the training is both sides - to those who want to bring issues to notice and to those who are going to respond to it.  

My heartfelt thanks to Manju who permitted me to use her name, my observations about her and recognizing what I said is true about her. Thanks to Parimala Hariprasad and Paul Carvalho to help me see blind spots in my thought and writing. Many thanks to my cousin Padmashree who is of K12 and took time to read this and tell what passages are simple and what are not. I have acted upon the information she provided. To bring this post to you, I have had to work, for more than 36 hours (over a period of one week) and what a moment for me to know you are reading it. Thank you! 

Wednesday, February 06, 2013

Testing for a product demo - experience report

~10 years ago

In 2003, I worked for Impulsesoft, a start-up company that claimed to be first in demonstrating CD Quality (which is 44.1 KHz sampling, at that time) stereo music over Bluetooth. I was extremely proud to have been a tester for the world's first Bluetooth Headphones. At that time, you may have called it a bleeding edge technology.

On a yet another beautiful Sunday morning I got a call from my manager to help someone in the marketing team who was flying to Germany for a conference. He was flying to a conference which had delegates who were potential buyers of our product. At that time, I don't know if the business model was B2B or B2C.  However, there were a few known crashes of the Bluetooth Headphones I was testing. I knew those crashes, after all, I found them.

My idea was to help him learn to not do anything that makes the headphones crash in front of the delegates. I gave him a list of do's and don'ts. I also demoed it to him on what would be happy path and what would be a dangerous path. I remember telling him to be careful of making the claims to potential buyers. On inquiring him I found he was seeking my help few hours before he was about to board a flight to Frankfurt. I did my best and wished him good luck for the demo.

2 days later, I get an email forwarded by my manager. With no surprises, the email had a content like, "Pradeep didn't test well, there are plenty of crashes and our potential buyers were not happy to experience it" written by the marketing fella whom I had coached on do's and dont's. I was called for a meeting to explain the same. I went with a print out of how we had already reported those bugs and with an explanation of how last minute prep for a demo like this is a bad idea.  Thankfully, my manager and the CTO were sane to understand. So, they said, "this is not a meeting to catch you responsible for it but to check how did you help the marketing guy".

I was excited about the whole experience. I started to think I could have done a bunch of stuff if I had time and I could really help customers. Later, I improved upon my approach to help customers and my employers if they were to ask me to "Test for Demo"!

~ 8 months ago

One of Moolya's customer is Cogknit. They are making products in the e-learning space to take the e-learning to i-learning and have been liking what Moolya has been doing to their product. They are boot strapped start up, young fellas, big dream and lot of sacrifice to get to a position where they are right now. About 8 months ago, they informed me that they were to be giving a demo and sought for my help.

I was so excited to bring in all my experience and expertise on this matter to Cogknit and gave this a high priority. I donned upon the role of Demo Test Architect without having to seek anyone's permission for it.

I had a meeting fixed with the founders of Cogknit and asked them a bunch of questions on

a) the conference - World Education Congress
b) the delegates (the potential buyers)
b) the objective
c) the demo plan they had (no matter how primitive it was)
d) their assumptions on what would not block them from delivering the demo

I set up a meeting with the developers from Multunus who were helping with the GUI and or front end, developers from Cogknit, testers from Moolya, the marketing fella - Deepak (co-founder of Cogknit), and Anuroop (the founder) with an objective to bring all to common ground and brief them about my plan and interest.

As a next step, I asked Anuroop and Deepak to give me a demo of what they intend to demo and I kept recording the steps they followed.

I did my home work on what could go wrong. For instance when Anuroop was demoing, he had already logged into Nimit (the web based i-learning product). I asked him to logout and then login again, start from first. Surprise! When he tried entering the password quickly, he made a mistake and bang, an error message, blood red in color appeared. At a demo, customers don't intend to see if errors are handled well but would want to see more of how the product works. There were too many blood red error info displayed for other actions that went wrong. If Anuroop were to accidentally type something in the search whose results are zero then the blood red appears which is good maybe for users but here there are no users except Anuroop  and Deepak who are going to be demoing.

My further homework and thinking suggested that the demo ready version of the product may not need to have these error messages at all. I held another meeting and requested the developers to give me a version that has no error messages displayed. "Remove all blood red" was my instruction. Probably, all of that code commented. I asked Anuroop to give me a demo again after the change happened. We also changed the password to something so simple that going wrong typing that is a sin :)

We went through multiple iterations of demo practice and kept tweaking the product to make it more suitable for demo.

I am guessing that Anuroop might have thought - why is this guy trying to teach me how to use the product I am building :) All for a good reason, dear Anuroop! The testers on the team supported me with a Don't Do Anything Like This list. As an example, to copy paste from their recommendation:

Do not drag & drop any book from the "Library" row to the Mashup tray The books other than Mashup shown in the "Library" row are either rented or bought contents. So, mashup of rented or bought contents are not allowed. 

Even if Anuroop accidentally did this, the product wouldn't shout, "Hey, here is an error message for you"!

My goal was to ensure Anuroop didn't do any of this. So every time he gives me a demo of what he thinks his demo is, I secretly run through the don't do this list to figure out if Anuroop is crossing the boundary of product areas marked as danger.

There was also a plan to make a feature work in the last minute and get it for the demo version. I humbly rejected the idea. No last minute changes to the product was my directive.

Once I had a version that looked to me as what can be presented during demo, I asked my fellow Moolya testers to run it through automated checks and exploratory tests and give me information that could make my decision change. I personally also toured the demo version of the product to find if my oracles help me be warned of something I should be. Things were starting to look OK barring a few minor changes needed.

The conference being on a week day and hosted on the same server where test instance and dev instance was running, I gave a directive to ask people to stop working on the dev / test / demo instance 2 hours before the time of the demo and wait for confirmation of demo over to re-start their work. This is to ensure nobody ends up doing anything to the server, even by accident. So, there was a stoppage of work for several hours during the demo.

I made a list of infrastructure requirements and checked the laptop they were getting for demo and made recommendations to turn off all alerts of the OS, Anti Virus, Apps and other nuisance that could disturb the demo from going smooth. I can't exactly remember if all of that was done but I guess Anuroop did mention that he would take care of it. Probably he did.

Then about internet connection for the laptop. I made recommendations to carry backup of internet dongles and to check at the venue a day before on the connectivity. Deepak and Anuroop did do a on the stage previous day test of internet connection and deemed it to be good enough.

During these days, the only question I kept asking myself, "What could I be missing?". A new idea kept emerging and I kept refining things better.

Last 2 days before the conference was more awesome adrenaline for me. Continuous stream of ideas and thought process. All through this period, I kept updating my notes and updating them to keep them reminded of what I am capturing and if it needs correction.

So the real D-Day came and I was nervously calling Ullas every one hour to check if Anuroop or Deepak were done with the demo and if they have any issues that they would need my help. I didn't do any other work that day and was totally thinking what would be going on for the demo. This was not nervousness, it was excitement to see the demo go well and feel happy about all the effort I took to get it going well.

The demo did happen, thankfully but the internet was slow. Thankfully nothing did time out or I heard that way. However, the next thing I include in my list is changing time out duration to ensure slow internet connections don't scare too much. The demo did generate good business interest for Cogknit and they got inquiries from Singapore and other countries that I don't exactly remember.

To add a feather to the crown, Nimit was awarded  The Most Innovative Learning Software Product. Here is a picture of Anuroop (right) and Deepak (left) receiving the award from his excellency Nurul Islam Nahid, Minister of Education - Bangladesh & David Namwandi, Minister of Education, Namibia

Anuroop and Deepak receiving The Most Innovative Learning Software Product from his excellency Nurul Islam Nahid, Minister of Education - Bangladesh & David Namwandi, Minister of Education, Namibia in World Education Congress 2012

Many thanks to Anuroop, Ullas and Deepak for being patient with me during the journey and allowing me to play the Demo Test Architect role. Equal good thanks to the developers at Multunus and Cogknit (especially to Himanshu) for supporting me on this. A special thanks to my own test team who have been helping Cogknit for more than a year now. Cogknit got their first big paying customer as well recently and they are sailing to get more.

I just hope, my colleague, Dhanasekar would be as proud of me as he is about Apple on how they prepare themselves for a product demo. More experience reports, coming soon.