Review of Pinduoduo's technical accident, what should programmers learn?
Every accident forces the technical team to grow. No one can guarantee that no bugs will be written and no mistakes will be made. What we have to do is to find the root of the problem after the accident occurs and fill in the holes in time to stop the loss.
In the early morning of January 20, 2019, some netizens claimed that there was a major bug in Pinduoduo, and users could receive and spend the 100-yuan no-threshold coupon at will. Everyone rushed to spread the word and got up in the middle of the night to collect coupons. Some users even received thousands of coupons. Smart users spent the coupons as quickly as possible, such as recharging China Mobile.
Recommended related articles: A programmer caused a major bug in Pinduoduo and was fined tens of millions
Pinduoduo responded early in the morning, "A black and gray production gang passed an expired The coupon loophole stole tens of millions of platform coupons and made illegal profits. In response to this behavior, the platform has repaired the loophole as soon as possible and is tracing the origin of the orders involved. At the same time, we have reported the case to the public security agency and We will actively cooperate with relevant departments to crack down on the black and gray industry gangs involved."
Subsequently, a Pinduoduo spokesperson said that the actual final asset loss may be less than 10 million yuan.
After this incident happened, there was an explosion in the technology circle. It may be due to rumors that "a bug may cause a loss of 20 billion to the company."
As a programmer, what I am more concerned about is, where did this bug come from? According to market rumors, we can roughly get some clues as follows. The authenticity of these clues has yet to be verified. They may not be the true circumstances of this incident, but this does not prevent us from using these clues to explore the enlightenment this accident has brought to us.
● Many people have made hundreds of thousands of dollars;
● This coupon is a test coupon;
● The system automatically launches the test coupon in the early morning;
● ● The operation and maintenance found that the system exploded and exceeded the threshold;
● The person involved manually offline the test coupon;
● The test coupon that was manually offline was online again at 8 a.m.
These clues seem to reasonably explain the deployment and operation of a major bug. From these clues, in addition to the design problems of the coupon itself, we can also see the chaos of operation and maintenance. How can test coupons be put online? The system is out of control, why are there no follow-up risk prevention measures? How can a test coupon that was manually offline be brought online again? Why are online and offline coupon operations so sloppy? If a software system is operated and maintained at this level, problems will occur sooner or later. If there is no problem yet, it can only be said that you are very lucky.
Coupon design issues
The first question that attracts us is, "Many people have made hundreds of thousands of dollars." This means that one person can receive thousands of coupons. Many people do this, which shows that the technical threshold for receiving no-threshold coupons is extremely low.
General coupons, similar to discount coupons, have usage thresholds, such as buying 100 yuan and getting a discount of 20 yuan. No-threshold coupons, as the name suggests, are coupons that have no usage threshold. A 100 yuan coupon can buy 100 yuan of goods, which is almost equivalent to cash. Since no-threshold coupons are similar to cash, they are significantly different from ordinary coupons.
Ignoring the wooly parties, Pinduoduo claims to have 300 million users. If each user can legally and reasonably receive the 100 yuan no-threshold coupon, this will require 30 billion yuan. There is almost no threshold for account registration. If WeChat’s 1 billion users legally and reasonably register, receive threshold-free coupons, and recharge their mobile phones, 100 billion yuan will be needed.
As of yesterday, Pinduoduo’s market capitalization was close to US$23 billion, which is equivalent to RMB 160 billion. The 100-yuan no-threshold voucher can be collected at will. This looks like a gesture of breaking up the company and giving bonuses to everyone. This is certainly not what is expected from a no-threshold coupon.
The no-threshold coupons that can be obtained casually are not qualified commercial designs no matter how you look at them. At the very least, set an upper limit on the quantity. Once everyone grabs it, it will be gone. If you give away a few million, it will be given away. Giving away tens of billions does not conform to normal business logic.
Generally speaking, there are many additional conditions for receiving even ordinary coupons. For example, an account can only receive it once, or only new accounts can receive it. Account authentication also requires many security measures, such as binding mobile phone numbers, binding devices, and using secure connections. Account authentication and management are the most basic functions of a service website. If a person can receive thousands of coupons, then the basic skill of account management cannot be considered as passing. If the account management level is not up to standard, the risk of this website will be worse than we imagined.
Such poor account management and such poor business design are so unexpected and inconsistent with normal logic. Therefore, I agree that this is just a test coupon and should not appear in a normal operating system. And if it is really a problem with test coupons, it will expose the chaos of software development and operation and maintenance.
Chaotic R&D and Operation and Maintenance
A test coupon came online automatically; after being offline manually, it automatically came online again. This product launch process is incredible. The release of a function must go through design, implementation, review, testing, and approval before it can be implemented into a formal system. As long as one of these links plays a role, the test coupons will not be online, let alone automatically.
After going online, there must be continuous risk monitoring. If the system exceeds the threshold and explodes, operation and maintenance can immediately obtain information about the explosion, such as accounts being unusually active in the middle of the night or coupon business being popular, and can also cut off this risk in a timely manner.
It can be seen that the reasonable restraint mechanism for operation and maintenance personnel is an issue that commercial companies must treat with caution. How can a random test coupon be used directly into the official system? Software operation and maintenance is a link that requires special attention to risk management and control, especially when the quality of the software has not kept up. Software operation and maintenance accidents can sometimes even subvert an industry.
In 2011, a digital certificate issuing agency issued multiple digital certificates to Google. Google has never applied for a digital certificate from this organization. In other words, the holder of the digital certificate is not Google. This holder can impersonate Google's website and steal user login information, including usernames and passwords. This means that either there is a problem with the company's technical level (hacker attack), or there is a problem with the company's operation and maintenance capabilities (random issuance of certificates). This security issue was exposed in August 2011, and almost all software giants immediately announced that they would block the digital certificate of this organization. In September, this institution with great market influence declared bankruptcy.
However, this is not the end, the doom of the digital certificate issuance industry has just begun. People seem to suddenly realize that information security cannot rely on digital certificate authorities. The security of a company with a market capitalization of US$400 billion cannot rely on the operational capabilities of a company with a market capitalization of US$4 billion. As a result, various new technologies emerged in the following years. If these new technologies are widely used, they will completely wipe out the entire digital certificate issuance industry. Such a day is not far away from us. Nowadays, the life of digital certificate issuing agencies is relatively bleak. Some are sold and some are scattered.
Hitchhiking, which frequently causes safety accidents, has a similar nature in the long run. In contrast, if all that is lost in an accident is money, the impact may be bearable. Hopefully all that will be lost is money, but I am not optimistic about this expectation.
Looking back to the source, operation and maintenance is so chaotic, which is generally inseparable from the quality of the software. For a serious software system, how to produce it, how to deploy it, how to operate it, how to authorize it, how to deal with crises, all these issues must be designed, implemented and planned. The party involved designed a threshold-free test coupon that can be run in the operating system and can be received unlimitedly. This exposed the poor quality of the software behind it and the loose and disorderly software development process. We often say that excellent software comes from excellent processes. A chaotic R&D process makes it difficult to produce high-quality products.
what should we do?
Ignorance is fearless. The reason why security issues are special is that if it does not happen, we may never know the existence of the problem, and of course we will not know how serious the problem is. Every security crisis should not be wasted. If we are the parties involved, what methods can we use to avoid similar accidents?
The most urgent thing is to pay off the account security debt as soon as possible. Otherwise, after this spread, a lot of eyes will be attracted to this piece of fat. The next wave of hacker attacks may already be on the way.
Next, consider the following things as soon as possible.
The first thing to do is to standardize the research and development process. The products produced under the first-class software development process will not be any worse no matter how bad they are. In this research and development process, programmers cannot act alone. Requirements need to be discussed, designs need to be previewed, functions need to be reviewed, codes need to be reviewed, software needs to be tested, and the system needs to be put into trial operation. Everyone will make mistakes. A few more pairs of eyes watching every step will greatly reduce the chance of making mistakes. Programmers can also grow quickly through the research and development process, further reducing the chance of errors. A good system can make people successful; a bad system can destroy people.
The second thing to do is to pay attention to the security of the code. Code security does not always refer to hacker intrusion. The use of this no-threshold coupon is a serious safety incident. Reflected at the code level, it may be that account management is unsafe, business logic is not verified, operation and maintenance authorization management is lax, and abnormal risks are not warned in time.
The third thing to do is to deduce the business design in advance. Even if there are no hackers, RMB 100 billion in no-threshold coupons is not a cost that any commercial organization is willing to pay. This is a kindergarten level mistake. If the business logic does not hold true, it means defective software requirements. Software built on buggy requirements will also be buggy.
The fourth thing to do is to improve the mechanism for product launch. Set checkpoints and pipelines for product launch. If any checkpoint fails, the pipeline will be interrupted and the product will not be launched online. These checkpoints include product trial operation, function approval, supporting monitoring measures, etc.
The fifth thing to do is to improve the risk prevention capabilities of operation and maintenance. A company with 300 million users, a market value of US$23 billion, and an e-commerce company is a target for hackers. In particular, user privacy information and cash flow are related to the life and death of the company. For a company of this size, having excellent risk prevention capabilities is the most basic requirement, not an icing on the cake. Active risk detection, timely warning, and rapid response are all measures that must keep up.
If the business design of the threshold-free coupon has been deduced, the software functions have been discussed, the implementation code has been reviewed, and the launch has been rehearsed, and the accident can be warned in time, as long as any of the links plays a role, this accident will not happen. It would be so tragic!
I understand the competitive pressure and motivation of a company to move forward at full speed regardless of everything and to trade quality for speed. However, when we pursue the current speed, we must also consider the future three feet away. Otherwise, the debt accumulated behind the butt will really become a big tail that cannot be shaken off.

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics



Pinduoduo software provides a lot of good products, you can buy them anytime and anywhere, and the quality of each product is strictly controlled, every product is genuine, and there are many preferential shopping discounts, allowing everyone to shop online Simply can not stop. Enter your mobile phone number to log in online, add multiple delivery addresses and contact information online, and check the latest logistics trends at any time. Product sections of different categories are open, search and swipe up and down to purchase and place orders, and experience convenience without leaving home. With the online shopping service, you can also view all purchase records, including the goods you have purchased, and receive dozens of shopping red envelopes and coupons for free. Now the editor has provided Pinduoduo users with a detailed online way to view purchased product records. method. 1. Open your phone and click on the Pinduoduo icon.

In Pinduoduo, the black label refers to the black "brand" logo, which is a kind of certification. Only stores that exceed a certain sales volume and are actually authorized brands can open it; in other words, the black label represents quality and credibility. , trustworthy and high-selling brands, brands with black labels will have certain advantages in Pinduoduo’s promotion and sales.

Pinduoduo app official download free latest version is a very good mobile shopping software. The platform provides a wide range of products. You can buy them anytime and anywhere. The shopping method is very simple. Open the search bar and enter the product name to find it accurately. Swipe up or down to choose the next one-click payment. You can enjoy many great discounts every day. You can get red envelope coupons of different amounts for free. You can also invite friends and family to join together for shopping, creating a comfortable and refreshing shopping method. If you want to buy There are all of them. Next, the editor will provide Pinduoduo partners with details on how to buy two products from the same store together. 1. Go to the [Pinduoduo] homepage with your mobile phone and select the product you want to buy. 2. After entering the product homepage, click the [Collect] button below. 3. Collection

Pinduoduo has launched the “select multiple models at once” function, which allows you to select different models of the same product and place an order at once. The editor has compiled some relevant content to share with you. Friends in need can come and take a look. How to buy different models of the same product on Pinduoduo 1. First open the page of the product you want to buy, click [Collection] in the lower left corner. 2. Then return to the personal center and use [Collection] to view the product you just collected. 3. Click [Select multiple models at once] below the product specifications to add products of different specifications. 4. After the purchase is completed, select the order and click the payment in the lower right corner.

1. How to add people as friends on Pinduoduo? How to add friends on Pinduoduo! 1. Open the Pinduoduo app, enter the homepage, and click the Pinduoduo icon at the top of the page. 2. After entering, select the portrait icon in the upper right corner. 3. You can see that there are three ways to add contacts: add friends, scan to add friends, and recommend friends. 4. Select the channel you want to add and send an application to add your own Pinduoduo friends.

What do game bugs mean? During the process of playing games, we often encounter some unexpected errors or problems, such as characters getting stuck, tasks being unable to continue, screen flickering, etc. These abnormal phenomena are called game bugs, that is, faults or errors in the game. In this article, we'll explore what game bugs mean and the impact they have on players and developers. Game bugs refer to errors that occur during the development or operation of the game, causing the game to fail to run normally or to behave unexpectedly. These errors may be due to

What is the most severe way to file a complaint against Pinduoduo? The software Pinduoduo brings convenience to us, but it also makes us feel entangled and upset. When the goods we buy are not suitable or we want to return them, we can go to the merchants to discuss them. Ichiban, but what should we do when we encounter some barbaric merchants? In fact, we can make complaints in order to protect the interests of our consumers. Below is the complaint method provided by the editor, I hope it can help you. The most severe way to complain about Pinduoduo is 12315. Pinduoduo’s customer service hotline is 4008822528. It is recommended to call during working hours. Pinduoduo’s customer service working hours are from 9:00 to 20:00. Method 2: Complain on Pinduoduo App; 1. Open Pinduoduo

How to turn off the use now, pay later function on Pinduoduo? Pinduoduo is a very smart software that allows users to buy things online and have them delivered to their door. There are many types of products on this software. Users can choose the products they need to buy. In order to allow To make it more convenient for users to use this software, a use now, pay later function has been launched. Many users want to cancel this function. Below, the editor has compiled the method of canceling the use now, pay later function for your reference. How to turn off the use now, pay later function on Pinduoduo. Turn it off on Pinduoduo. 1. After entering Pinduoduo’s personal homepage, click “Settings”. 2. In the settings, click "Use now, pay later settings". 3.