BIT302 Software Engineering

Software EngineeringUnit 1420 min read

Software Issues & Challenges: Risks, Ethics, Scalability & Maintenance

Unit 14 of Software Engineering explores critical challenges in software development—technical debt, ethical dilemmas, scalability bottlenecks, and maintenance pitfalls—with real-world examples from Nepali apps (eSewa, Daraz) and global tech (Google, WhatsApp). Learn how to identify risks, apply mitigation strategies,

TAKEAWAYS:

  • Software issues span technical (e.g., scalability, security), ethical (e.g., bias in AI), and economic (e.g., maintenance costs) dimensions, requiring proactive risk management.
  • Ethical challenges (privacy, transparency) are legally binding in Nepal (e.g., Digital Transaction Act 2018) and globally (e.g., GDPR), demanding explicit design considerations.
  • Scalability trade-offs (e.g., monolithic vs. microservices) directly impact performance—Daraz’s peak sales (e.g., Dashain) reveal how poor design causes outages.
  • Technical debt accumulates from shortcuts (e.g., untested code) and costs 1.5x–2x more to fix later—Google’s Site Reliability Engineering team tracks this rigorously.
  • Maintenance challenges (e.g., legacy systems like NTC’s billing software) account for 60–80% of total software costs; incremental updates are key.
  • Open-source risks (e.g., licensing conflicts in Kathmandu’s OpenKM deployments) require clear governance—MIT vs. GPL licenses behave differently in commercial use.

1. Defining Software Issues: Scope and Classification

Software issues are unintended problems that arise during development, deployment, or maintenance, categorized by their root cause:

mindmap
  root((Software Issues))
    Technical
      Scalability: "Load handling (e.g., Pathao’s 1M+ daily rides)"
      Security: "Vulnerabilities (e.g., eSewa’s 2021 breach)"
      Performance: "Latency (e.g., NEPSE’s trading delays)"
    Ethical
      Privacy: "Data misuse (e.g., WhatsApp’s end-to-end encryption debates)"
      Bias: "Algorithmic discrimination (e.g., loan approvals in banks)"
      Transparency: "Black-box AI (e.g., Ncell’s churn prediction models)"
    Economic
      Maintenance Costs: "Legacy systems (e.g., NTC’s COBOL-based tools)"
      Licensing: "Open-source compliance (e.g., Daraz’s Apache vs. GPL)"
    Organizational
      Communication Gaps: "Misaligned stakeholders (e.g., Kathmandu traffic app failures)"
      Skill Shortages: "Lack of DevOps expertise in Nepali startups"

Why it matters:

  • 70% of software projects fail due to unaddressed issues (Standish Group).
  • Nepal’s Software Industry Association reports that 50% of local apps face scalability issues during festivals (e.g., Dashain, Tihar).

2. Real-World Examples: Where These Issues Surface

A. Scalability in Nepali Apps

Example 1: eSewa’s Peak Load Handling

  • Issue: During Dashain, eSewa processes 500,000+ transactions/hour (vs. 50K on normal days).
  • Challenge: Poorly optimized databases cause 3–5 second delays, leading to abandoned payments.
  • Solution: Uses read replicas and caching layers (Redis) to distribute load.
    sequenceDiagram
      participant User
      participant LoadBalancer
      participant AppServer
      participant DB_Primary
      participant DB_Replica
      User->>LoadBalancer: Payment Request (500K/h)
      LoadBalancer->>AppServer: Route to least-loaded node
      AppServer->>DB_Replica: Read (90% of queries)
      DB_Primary-->>AppServer: Write (10%)
      AppServer-->>User: Confirmation

Example 2: Daraz’s Microservices Architecture

  • Issue: Monolithic design slowed order processing during sales (e.g., 6.16 event).
  • Fix: Split into 12 microservices (Inventory, Payments, Logistics), reducing latency by 60%. Trade-off: Added complexity in debugging (e.g., tracing a failed order across services).

B. Ethical Dilemmas in Data-Driven Apps

Example 1: Ncell’s Customer Churn Prediction

  • Issue: AI model flagged low-income users as "high-risk" due to call-drop patterns, leading to preemptive service suspensions.
  • Ethical Conflict:
    • Transparency: Users weren’t informed about the AI’s role.
    • Bias: Model trained on data from urban areas only, misclassifying rural users.
  • Solution: Ncell now uses explainable AI (SHAP values) and human review for critical decisions.

Example 2: Khalti’s Privacy vs. Convenience

  • Issue: Khalti’s biometric authentication (fingerprint/face ID) raised concerns about data leaks if devices are hacked.
  • Nepal’s Legal Framework:
    • Digital Transaction Act 2018 mandates user consent for biometric data.
    • Privacy Act 2018 requires data minimization (only collect what’s necessary).
  • Khalti’s Approach:
    • On-device processing: Biometric data never leaves the phone.
    • Anonymization: Transaction IDs replace user names in logs.

C. Technical Debt in Legacy Systems

Example 1: NTC’s Billing Software

  • Issue: Written in COBOL (1990s), the system requires manual patches for new tariffs (e.g., Smart Prepaid plans).
  • Cost of Inaction:
    • $200K/year in emergency fixes.
    • 3-day outages during load shedding (no automated failover).
  • Proposed Fix: Gradual migration to microservices (e.g., separate billing, customer service modules).

Example 2: Google’s Technical Debt Tracking

  • Tool: Monorail (internal issue tracker) flags debt like:
    • "Unoptimized SQL queries" (cost: $50K/month in server costs).
    • "Duplicate code" (e.g., payment validation logic in 3 modules).
  • Mitigation: 20% of dev time is allocated to debt repayment (per Google SRE principles).

3. Key Software Challenges: Deep Dive

A. Scalability Challenges

Definition: The ability to handle growing workloads (users, data, transactions) without performance degradation.

Common Bottlenecks:

Layer Bottleneck Example in Nepal Solution
Database Slow queries NEPSE’s trading system (10K+ orders/sec) Indexing, sharding, read replicas
Network Latency Pathao’s rider-app sync with drivers Edge computing (local servers)
API Throttling Daraz’s payment gateway during sales Rate limiting, queue systems
Frontend Rendering delays eSewa’s web app on low-end phones Progressive loading, lazy rendering

Worked Example: Kathmandu Traffic Routes App

  • Problem: App crashes when >500 users track routes simultaneously (e.g., during Bhai Tika festival).
  • Root Cause:
    • Single PostgreSQL database handling all queries.
    • No caching for static data (e.g., road maps).
  • Fix:
    1. Database Sharding: Split by regions (e.g., kathmandu_routes, pokhara_routes).
    2. CDN for Maps: Serve static maps from Cloudflare.
    3. Load Testing: Simulate 10K users with Locust.
    [User] --> [CDN (Maps)] --> [Load Balancer]
                       |
    [User] --> [API Gateway] --> [Microservices]
                       |
    [Microservices] --> [Sharded DBs] (kathmandu/pokhara/lalitpur)
    

B. Ethical Challenges in Software

Framework for Ethical Decision-Making:

  1. Identify Stakeholders: Users, developers, regulators (e.g., Office of the Attorney General, Nepal).
  2. Assess Risks: Privacy, bias, transparency.
  3. Apply Guidelines:
    • Nepal: Digital Transaction Act 2018, Privacy Act 2018.
    • Global: GDPR (EU), CCPA (USA).
  4. Document Decisions: Keep an ethics log (e.g., WhatsApp’s Ethics and Policy Committee reports).

Case Study: AI in Loan Approvals (Nepal’s Banks)

  • Issue: AI model rejected 30% of rural loan applications due to lack of credit history.
  • Ethical Violation: Exclusion of marginalized groups.
  • Fix:
    • Alternative Data: Include mobile money (Khalti) and utility bill payments.
    • Human Review: Override AI decisions for <50K loans/year.

C. Technical Debt: Causes and Costs

Definition: The implicit cost of choosing quick fixes over long-term solutions.

How It Accumulates:

stateDiagram-v2
  [*] --> Shortcut
  Shortcut --> UnwrittenTests: "Skipping tests for speed"
  UnwrittenTests --> Bugs: "Undetected issues"
  Bugs --> Workarounds: "Patches instead of fixes"
  Workarounds --> TechnicalDebt: "Growing complexity"
  TechnicalDebt --> [*]: "Project collapse"

Types of Technical Debt:

Type Example Cost to Fix
Code Debt Uncommented spaghetti code 1.5x original effort
Design Debt Monolithic architecture 2x refactoring cost
Test Debt No automated tests 3x bug-fix time
Documentation Debt Outdated API docs 1.2x onboarding time

Worked Example: WhatsApp’s End-to-End Encryption

  • Initial Debt: Early versions used centralized encryption keys (security risk).
  • Fix: Migrated to Signal Protocol (decentralized keys).
  • Cost: $50M and 2 years of development, but prevented $500M in potential breaches.

4. Mitigation Strategies

A. Proactive Risk Management

Step-by-Step Process:

  1. Identify Risks: Use SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).
  2. Prioritize: Assign risk scores (Likelihood × Impact).
  3. Mitigate:
    • Scalability: Load testing, auto-scaling (e.g., AWS Auto Scaling).
    • Security: Penetration testing (e.g., Ncell’s annual audits).
    • Ethics: Bias audits (e.g., Google’s What-If Tool for ML models).
  4. Monitor: Track metrics (e.g., error rates, user complaints).

Example: Daraz’s Risk Management for 6.16 Sales

Risk Mitigation Strategy Tools Used
Traffic spikes Auto-scaling Kubernetes pods AWS EKS
Payment failures Circuit breakers for payment gateways Hystrix
Fraudulent orders AI-based anomaly detection TensorFlow Serving

B. Ethical Software Development

Checklist for Nepali Developers:

  • Data Minimization: Collect only what’s necessary (e.g., eSewa asks for minimal KYC).
  • Bias Audits: Test models on diverse datasets (e.g., Ncell’s rural/urban split).
  • Transparency: Disclose AI use (e.g., Khalti’s Privacy Policy section on biometrics).
  • User Control: Allow opt-outs (e.g., NTC’s Do Not Call registry).

Example: YouTube’s Ethical AI

  • Issue: Recommendation algorithm amplified extremist content.
  • Fix:
    • Human-in-the-loop: Reviewers flag 10% of controversial videos.
    • Transparency Reports: Publish data on demographic bias.

C. Managing Technical Debt

Strategies:

  1. Debt Tracking: Use tools like SonarQube (for code quality) or JIRA (for tracking debt tickets).
  2. Allocation: Dedicate 10–20% of sprint time to debt repayment (per Google’s SRE model).
  3. Prioritization: Fix high-interest debt first (e.g., security flaws > minor code smells).

Example: Google’s Debt Repayment

  • Process:
    1. Identify: Engineers flag debt in code reviews.
    2. Prioritize: Product managers assign debt tickets (e.g., "Fix payment retry logic").
    3. Repay: Dedicated SRE teams work on fixes during low-traffic periods.

5. Software Maintenance Challenges

Why Maintenance is Critical:

  • Cost: 60–80% of total software lifecycle cost (IBM study).
  • Nepal Context: 80% of Nepali apps are <5 years old, with no formal maintenance plans.

Common Maintenance Issues:

Issue Example Solution
Feature Creep eSewa adding 10 new features/year Agile backlog prioritization
Legacy Integration NTC’s COBOL system + new cloud APIs API gateways, wrappers
User Expectations Daraz users demand real-time tracking Microservices for logistics

Worked Example: NEPSE’s Trading System

  • Problem: 2003-era system can’t handle high-frequency trading (HFT).
  • Maintenance Plan:
    1. Phase 1 (2024): Add REST APIs for mobile apps.
    2. Phase 2 (2025): Migrate order matching to Kafka for real-time processing.
    3. Phase 3 (2026): Replace COBOL core with Java microservices.

6. Open-Source Software (OSS) Challenges

Why Nepal’s Devs Struggle with OSS:

  • Licensing Confusion: MIT vs. GPL vs. Apache licenses have different commercial use rules.
  • Support Gaps: No local OSS communities for troubleshooting (vs. Stack Overflow for global issues).
  • Security Risks: Unpatched vulnerabilities (e.g., Log4j in open-source libraries).

Example: Kathmandu’s OpenKM Deployment

  • Issue: Used GPL-licensed OpenKM for document management, but modified the source code.
  • Problem: GPL requires open-sourcing modifications—company hesitated due to IP concerns.
  • Solution: Switched to Apache-licensed alternatives (e.g., Alfresco).

Licensing Comparison:

License Commercial Use Modifications Example Projects
MIT Allowed Allowed React, jQuery
GPL Allowed (if open-source) Must open-source Linux Kernel
Apache Allowed Allowed Hadoop, Kafka

Exam Tip: How to Score Full Marks

1. Structured Answers for Descriptive Questions

Question: "Explain the process of software configuration management." How to Answer for 10 Marks:

  1. Definition (1 mark): "Software Configuration Management (SCM) is the process of tracking and controlling changes to software code, documentation, and dependencies to ensure consistency and traceability."
  2. Key Activities (4 marks):
    • Version Control: Use Git (e.g., GitHub, GitLab).
    • Build Automation: Tools like Jenkins or Maven.
    • Change Management: Track changes via JIRA or Trac.
    • Release Management: Tag versions (e.g., v1.0.0).
  3. Tools (2 marks): Mention Git, SVN, Docker, Ansible.
  4. Real-World Example (2 marks): "eSewa uses GitLab CI/CD to automate testing and deployment during festivals, ensuring no bugs slip into production."
  5. Diagram (1 mark): Draw a CI/CD pipeline (see below).
sequenceDiagram
  participant Dev
  participant Git
  participant Jenkins
  participant TestEnv
  participant Prod
  Dev->>Git: Commit code
  Git->>Jenkins: Trigger build
  Jenkins->>TestEnv: Run tests
  alt Tests Pass
    Jenkins->>Prod: Deploy
  else Tests Fail
    Jenkins->>Dev: Notify
  end

2. Short Notes: Bullet Points + Examples

Question: "Write short notes on: a) Agile software development b) Context model" Answer for 5 Marks Each:

a) Agile Software Development (5 marks)

  • Definition: Iterative approach with short cycles (sprints), customer feedback, and adaptive planning.
  • Core Principles (3 marks):
    • Individuals and interactions > Processes/tools.
    • Working software > Comprehensive documentation.
    • Customer collaboration > Contract negotiation.
  • Methodologies (1 mark): Scrum, Kanban, Extreme Programming (XP).
  • Example (1 mark): "Pathao uses 2-week sprints in Scrum to release new rider features weekly."

b) Context Model (5 marks)

  • Definition: Visualizes system boundaries, actors, and external dependencies.
  • Components (3 marks):
    • System Scope: What’s included/excluded.
    • Stakeholders: Users, admins, third parties (e.g., Ncell’s IVR system).
    • External Systems: APIs, databases (e.g., eSewa’s payment gateway).
  • Diagram (1 mark): Draw a context diagram (see below).
  • Use Case (1 mark): "Nepal’s e-Governance portal uses context models to show how citizens, ministries, and banks interact."
erDiagram
  Citizen ||--o{ eGovernance : "uses"
  eGovernance ||--|{ Ministry : "interacts with"
  eGovernance ||--|{ Bank : "integrates with"

3. Diagram-Based Questions

Question: "Explain incremental delivery approach with a neat diagram." Answer (8 marks):

  1. Definition (1 mark): "Delivering software in small, functional increments to gather early feedback."
  2. Phases (3 marks):
    • Plan: Define MVP (Minimum Viable Product).
    • Develop: Build small modules (e.g., Daraz’s cart system before checkout).
    • Review: Get user feedback (e.g., Pathao’s beta tests with 100 riders).
    • Iterate: Improve based on feedback.
  3. Diagram (3 marks): Draw the incremental delivery cycle (see below).
  4. Example (1 mark): "eSewa launched mobile payments incrementally: first P2P transfers, then bill payments, then loans."
flowchart LR
  A["Plan MVP"] --> B["Develop Increment 1"]
  B --> C["Review Feedback"]
  C -->|"Improve"| D["Develop Increment 2"]
  D --> C
  C --> E["Final Product"]

4. Comparison Tables

Question: "Compare monolithic and microservices architecture." Answer (6 marks):

Aspect Monolithic Microservices
Definition Single codebase, tightly coupled Small, independent services
Scalability Scale entire app (inefficient) Scale only needed services (e.g., Daraz’s payment service)
Deployment Slow (redeploy entire app) Fast (deploy individual services)
Complexity Low High (orchestration needed)
Fault Isolation One crash = whole app down Isolated failures (e.g., NEPSE’s order service fails, UI still works)
Example eSewa’s early versions Google’s YouTube (video, comments, recommendations as separate services)

In the Real World

  1. eSewa’s Scalability Challenge

    • Issue: During Dashain, transaction volume spikes 10x, causing 5-second delays.
    • Solution: Uses Kubernetes auto-scaling and Redis caching to handle 500K transactions/hour.
    • Lesson: Always design for peak loads, not average usage.
  2. Ncell’s Ethical AI Dilemma

    • Issue: AI model misclassified rural users as "low-value," leading to poor service.
    • Fix: Added human reviewers for <50K loans/year and retrained the model with rural data.
    • Lesson: Bias audits are non-negotiable in high-stakes systems.
  3. Daraz’s Technical Debt Crisis

    • Issue: Monolithic design caused 3-hour outages during 6.16 sales.
    • Fix: Migrated to microservices, reducing downtime to <5 minutes.
    • Cost: $1M in development, but saved $5M in lost sales.
  4. NTC’s Legacy System Struggle

    • Issue: COBOL-based billing system can’t handle prepaid plans.
    • Workaround: Manual patches cost $200K/year.
    • Solution: Incremental migration to Java microservices (phased over 3 years).
  5. Khalti’s Privacy vs. Convenience Trade-off

    • Issue: Biometric auth speeds up payments but raises privacy concerns.
    • Compromise: On-device processing (data never leaves the phone) + GDPR-compliant policies.
    • Lesson: Transparency builds trust—Khalti’s user base grew 30% after clarifying data use.

Final Checklist for Exam Readiness

  • Memorize definitions: Software issues, technical debt, ethical challenges.
  • Know tools: Git, Jenkins, SonarQube, Kubernetes, LoadRunner.
  • Practice diagrams: Context models, incremental delivery, CI/CD pipelines.
  • Relate to Nepal: eSewa, Daraz, Ncell, NTC, NEPSE examples.
  • Understand trade-offs: Scalability vs. cost, ethics vs. convenience.
  • Review past papers: Focus on diagram-based and short-answer questions.

git workflow diagramBranching strategies (e.g., GitFlow) used in Nepali startups. (Image: TheresNoTime, CC BY-SA 4.0, via Wikimedia Commons)

Based on the TU BIT syllabus for Software Engineering (BIT302), unit 14.

Discussion

Loading…