Software EngineeringUnit 1420 min read
Software Issues & Challenges: Risks, Ethics, Scalability & Maintenance
Unit 14 of Software Engineering explores critical challenges in software development—technical debt, ethical dilemmas, scalability bottlenecks, and maintenance pitfalls—with real-world examples from Nepali apps (eSewa, Daraz) and global tech (Google, WhatsApp). Learn how to identify risks, apply mitigation strategies,
TAKEAWAYS:
- Software issues span technical (e.g., scalability, security), ethical (e.g., bias in AI), and economic (e.g., maintenance costs) dimensions, requiring proactive risk management.
- Ethical challenges (privacy, transparency) are legally binding in Nepal (e.g., Digital Transaction Act 2018) and globally (e.g., GDPR), demanding explicit design considerations.
- Scalability trade-offs (e.g., monolithic vs. microservices) directly impact performance—Daraz’s peak sales (e.g., Dashain) reveal how poor design causes outages.
- Technical debt accumulates from shortcuts (e.g., untested code) and costs 1.5x–2x more to fix later—Google’s Site Reliability Engineering team tracks this rigorously.
- Maintenance challenges (e.g., legacy systems like NTC’s billing software) account for 60–80% of total software costs; incremental updates are key.
- Open-source risks (e.g., licensing conflicts in Kathmandu’s OpenKM deployments) require clear governance—MIT vs. GPL licenses behave differently in commercial use.
1. Defining Software Issues: Scope and Classification
Software issues are unintended problems that arise during development, deployment, or maintenance, categorized by their root cause:
mindmap
root((Software Issues))
Technical
Scalability: "Load handling (e.g., Pathao’s 1M+ daily rides)"
Security: "Vulnerabilities (e.g., eSewa’s 2021 breach)"
Performance: "Latency (e.g., NEPSE’s trading delays)"
Ethical
Privacy: "Data misuse (e.g., WhatsApp’s end-to-end encryption debates)"
Bias: "Algorithmic discrimination (e.g., loan approvals in banks)"
Transparency: "Black-box AI (e.g., Ncell’s churn prediction models)"
Economic
Maintenance Costs: "Legacy systems (e.g., NTC’s COBOL-based tools)"
Licensing: "Open-source compliance (e.g., Daraz’s Apache vs. GPL)"
Organizational
Communication Gaps: "Misaligned stakeholders (e.g., Kathmandu traffic app failures)"
Skill Shortages: "Lack of DevOps expertise in Nepali startups"Why it matters:
- 70% of software projects fail due to unaddressed issues (Standish Group).
- Nepal’s Software Industry Association reports that 50% of local apps face scalability issues during festivals (e.g., Dashain, Tihar).
2. Real-World Examples: Where These Issues Surface
A. Scalability in Nepali Apps
Example 1: eSewa’s Peak Load Handling
- Issue: During Dashain, eSewa processes 500,000+ transactions/hour (vs. 50K on normal days).
- Challenge: Poorly optimized databases cause 3–5 second delays, leading to abandoned payments.
- Solution: Uses read replicas and caching layers (Redis) to distribute load.
sequenceDiagram participant User participant LoadBalancer participant AppServer participant DB_Primary participant DB_Replica User->>LoadBalancer: Payment Request (500K/h) LoadBalancer->>AppServer: Route to least-loaded node AppServer->>DB_Replica: Read (90% of queries) DB_Primary-->>AppServer: Write (10%) AppServer-->>User: Confirmation
Example 2: Daraz’s Microservices Architecture
- Issue: Monolithic design slowed order processing during sales (e.g., 6.16 event).
- Fix: Split into 12 microservices (Inventory, Payments, Logistics), reducing latency by 60%. Trade-off: Added complexity in debugging (e.g., tracing a failed order across services).
B. Ethical Dilemmas in Data-Driven Apps
Example 1: Ncell’s Customer Churn Prediction
- Issue: AI model flagged low-income users as "high-risk" due to call-drop patterns, leading to preemptive service suspensions.
- Ethical Conflict:
- Transparency: Users weren’t informed about the AI’s role.
- Bias: Model trained on data from urban areas only, misclassifying rural users.
- Solution: Ncell now uses explainable AI (SHAP values) and human review for critical decisions.
Example 2: Khalti’s Privacy vs. Convenience
- Issue: Khalti’s biometric authentication (fingerprint/face ID) raised concerns about data leaks if devices are hacked.
- Nepal’s Legal Framework:
- Digital Transaction Act 2018 mandates user consent for biometric data.
- Privacy Act 2018 requires data minimization (only collect what’s necessary).
- Khalti’s Approach:
- On-device processing: Biometric data never leaves the phone.
- Anonymization: Transaction IDs replace user names in logs.
C. Technical Debt in Legacy Systems
Example 1: NTC’s Billing Software
- Issue: Written in COBOL (1990s), the system requires manual patches for new tariffs (e.g., Smart Prepaid plans).
- Cost of Inaction:
- $200K/year in emergency fixes.
- 3-day outages during load shedding (no automated failover).
- Proposed Fix: Gradual migration to microservices (e.g., separate billing, customer service modules).
Example 2: Google’s Technical Debt Tracking
- Tool: Monorail (internal issue tracker) flags debt like:
- "Unoptimized SQL queries" (cost: $50K/month in server costs).
- "Duplicate code" (e.g., payment validation logic in 3 modules).
- Mitigation: 20% of dev time is allocated to debt repayment (per Google SRE principles).
3. Key Software Challenges: Deep Dive
A. Scalability Challenges
Definition: The ability to handle growing workloads (users, data, transactions) without performance degradation.
Common Bottlenecks:
| Layer | Bottleneck | Example in Nepal | Solution |
|---|---|---|---|
| Database | Slow queries | NEPSE’s trading system (10K+ orders/sec) | Indexing, sharding, read replicas |
| Network | Latency | Pathao’s rider-app sync with drivers | Edge computing (local servers) |
| API | Throttling | Daraz’s payment gateway during sales | Rate limiting, queue systems |
| Frontend | Rendering delays | eSewa’s web app on low-end phones | Progressive loading, lazy rendering |
Worked Example: Kathmandu Traffic Routes App
- Problem: App crashes when >500 users track routes simultaneously (e.g., during Bhai Tika festival).
- Root Cause:
- Single PostgreSQL database handling all queries.
- No caching for static data (e.g., road maps).
- Fix:
- Database Sharding: Split by regions (e.g.,
kathmandu_routes,pokhara_routes). - CDN for Maps: Serve static maps from Cloudflare.
- Load Testing: Simulate 10K users with Locust.
[User] --> [CDN (Maps)] --> [Load Balancer] | [User] --> [API Gateway] --> [Microservices] | [Microservices] --> [Sharded DBs] (kathmandu/pokhara/lalitpur) - Database Sharding: Split by regions (e.g.,
B. Ethical Challenges in Software
Framework for Ethical Decision-Making:
- Identify Stakeholders: Users, developers, regulators (e.g., Office of the Attorney General, Nepal).
- Assess Risks: Privacy, bias, transparency.
- Apply Guidelines:
- Nepal: Digital Transaction Act 2018, Privacy Act 2018.
- Global: GDPR (EU), CCPA (USA).
- Document Decisions: Keep an ethics log (e.g., WhatsApp’s Ethics and Policy Committee reports).
Case Study: AI in Loan Approvals (Nepal’s Banks)
- Issue: AI model rejected 30% of rural loan applications due to lack of credit history.
- Ethical Violation: Exclusion of marginalized groups.
- Fix:
- Alternative Data: Include mobile money (Khalti) and utility bill payments.
- Human Review: Override AI decisions for <50K loans/year.
C. Technical Debt: Causes and Costs
Definition: The implicit cost of choosing quick fixes over long-term solutions.
How It Accumulates:
stateDiagram-v2 [*] --> Shortcut Shortcut --> UnwrittenTests: "Skipping tests for speed" UnwrittenTests --> Bugs: "Undetected issues" Bugs --> Workarounds: "Patches instead of fixes" Workarounds --> TechnicalDebt: "Growing complexity" TechnicalDebt --> [*]: "Project collapse"
Types of Technical Debt:
| Type | Example | Cost to Fix |
|---|---|---|
| Code Debt | Uncommented spaghetti code | 1.5x original effort |
| Design Debt | Monolithic architecture | 2x refactoring cost |
| Test Debt | No automated tests | 3x bug-fix time |
| Documentation Debt | Outdated API docs | 1.2x onboarding time |
Worked Example: WhatsApp’s End-to-End Encryption
- Initial Debt: Early versions used centralized encryption keys (security risk).
- Fix: Migrated to Signal Protocol (decentralized keys).
- Cost: $50M and 2 years of development, but prevented $500M in potential breaches.
4. Mitigation Strategies
A. Proactive Risk Management
Step-by-Step Process:
- Identify Risks: Use SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).
- Prioritize: Assign risk scores (Likelihood × Impact).
- Mitigate:
- Scalability: Load testing, auto-scaling (e.g., AWS Auto Scaling).
- Security: Penetration testing (e.g., Ncell’s annual audits).
- Ethics: Bias audits (e.g., Google’s What-If Tool for ML models).
- Monitor: Track metrics (e.g., error rates, user complaints).
Example: Daraz’s Risk Management for 6.16 Sales
| Risk | Mitigation Strategy | Tools Used |
|---|---|---|
| Traffic spikes | Auto-scaling Kubernetes pods | AWS EKS |
| Payment failures | Circuit breakers for payment gateways | Hystrix |
| Fraudulent orders | AI-based anomaly detection | TensorFlow Serving |
B. Ethical Software Development
Checklist for Nepali Developers:
- Data Minimization: Collect only what’s necessary (e.g., eSewa asks for minimal KYC).
- Bias Audits: Test models on diverse datasets (e.g., Ncell’s rural/urban split).
- Transparency: Disclose AI use (e.g., Khalti’s Privacy Policy section on biometrics).
- User Control: Allow opt-outs (e.g., NTC’s Do Not Call registry).
Example: YouTube’s Ethical AI
- Issue: Recommendation algorithm amplified extremist content.
- Fix:
- Human-in-the-loop: Reviewers flag 10% of controversial videos.
- Transparency Reports: Publish data on demographic bias.
C. Managing Technical Debt
Strategies:
- Debt Tracking: Use tools like SonarQube (for code quality) or JIRA (for tracking debt tickets).
- Allocation: Dedicate 10–20% of sprint time to debt repayment (per Google’s SRE model).
- Prioritization: Fix high-interest debt first (e.g., security flaws > minor code smells).
Example: Google’s Debt Repayment
- Process:
- Identify: Engineers flag debt in code reviews.
- Prioritize: Product managers assign debt tickets (e.g., "Fix payment retry logic").
- Repay: Dedicated SRE teams work on fixes during low-traffic periods.
5. Software Maintenance Challenges
Why Maintenance is Critical:
- Cost: 60–80% of total software lifecycle cost (IBM study).
- Nepal Context: 80% of Nepali apps are <5 years old, with no formal maintenance plans.
Common Maintenance Issues:
| Issue | Example | Solution |
|---|---|---|
| Feature Creep | eSewa adding 10 new features/year | Agile backlog prioritization |
| Legacy Integration | NTC’s COBOL system + new cloud APIs | API gateways, wrappers |
| User Expectations | Daraz users demand real-time tracking | Microservices for logistics |
Worked Example: NEPSE’s Trading System
- Problem: 2003-era system can’t handle high-frequency trading (HFT).
- Maintenance Plan:
- Phase 1 (2024): Add REST APIs for mobile apps.
- Phase 2 (2025): Migrate order matching to Kafka for real-time processing.
- Phase 3 (2026): Replace COBOL core with Java microservices.
6. Open-Source Software (OSS) Challenges
Why Nepal’s Devs Struggle with OSS:
- Licensing Confusion: MIT vs. GPL vs. Apache licenses have different commercial use rules.
- Support Gaps: No local OSS communities for troubleshooting (vs. Stack Overflow for global issues).
- Security Risks: Unpatched vulnerabilities (e.g., Log4j in open-source libraries).
Example: Kathmandu’s OpenKM Deployment
- Issue: Used GPL-licensed OpenKM for document management, but modified the source code.
- Problem: GPL requires open-sourcing modifications—company hesitated due to IP concerns.
- Solution: Switched to Apache-licensed alternatives (e.g., Alfresco).
Licensing Comparison:
| License | Commercial Use | Modifications | Example Projects |
|---|---|---|---|
| MIT | Allowed | Allowed | React, jQuery |
| GPL | Allowed (if open-source) | Must open-source | Linux Kernel |
| Apache | Allowed | Allowed | Hadoop, Kafka |
Exam Tip: How to Score Full Marks
1. Structured Answers for Descriptive Questions
Question: "Explain the process of software configuration management." How to Answer for 10 Marks:
- Definition (1 mark): "Software Configuration Management (SCM) is the process of tracking and controlling changes to software code, documentation, and dependencies to ensure consistency and traceability."
- Key Activities (4 marks):
- Version Control: Use Git (e.g., GitHub, GitLab).
- Build Automation: Tools like Jenkins or Maven.
- Change Management: Track changes via JIRA or Trac.
- Release Management: Tag versions (e.g.,
v1.0.0).
- Tools (2 marks): Mention Git, SVN, Docker, Ansible.
- Real-World Example (2 marks): "eSewa uses GitLab CI/CD to automate testing and deployment during festivals, ensuring no bugs slip into production."
- Diagram (1 mark): Draw a CI/CD pipeline (see below).
sequenceDiagram
participant Dev
participant Git
participant Jenkins
participant TestEnv
participant Prod
Dev->>Git: Commit code
Git->>Jenkins: Trigger build
Jenkins->>TestEnv: Run tests
alt Tests Pass
Jenkins->>Prod: Deploy
else Tests Fail
Jenkins->>Dev: Notify
end2. Short Notes: Bullet Points + Examples
Question: "Write short notes on: a) Agile software development b) Context model" Answer for 5 Marks Each:
a) Agile Software Development (5 marks)
- Definition: Iterative approach with short cycles (sprints), customer feedback, and adaptive planning.
- Core Principles (3 marks):
- Individuals and interactions > Processes/tools.
- Working software > Comprehensive documentation.
- Customer collaboration > Contract negotiation.
- Methodologies (1 mark): Scrum, Kanban, Extreme Programming (XP).
- Example (1 mark): "Pathao uses 2-week sprints in Scrum to release new rider features weekly."
b) Context Model (5 marks)
- Definition: Visualizes system boundaries, actors, and external dependencies.
- Components (3 marks):
- System Scope: What’s included/excluded.
- Stakeholders: Users, admins, third parties (e.g., Ncell’s IVR system).
- External Systems: APIs, databases (e.g., eSewa’s payment gateway).
- Diagram (1 mark): Draw a context diagram (see below).
- Use Case (1 mark): "Nepal’s e-Governance portal uses context models to show how citizens, ministries, and banks interact."
erDiagram
Citizen ||--o{ eGovernance : "uses"
eGovernance ||--|{ Ministry : "interacts with"
eGovernance ||--|{ Bank : "integrates with"3. Diagram-Based Questions
Question: "Explain incremental delivery approach with a neat diagram." Answer (8 marks):
- Definition (1 mark): "Delivering software in small, functional increments to gather early feedback."
- Phases (3 marks):
- Plan: Define MVP (Minimum Viable Product).
- Develop: Build small modules (e.g., Daraz’s cart system before checkout).
- Review: Get user feedback (e.g., Pathao’s beta tests with 100 riders).
- Iterate: Improve based on feedback.
- Diagram (3 marks): Draw the incremental delivery cycle (see below).
- Example (1 mark): "eSewa launched mobile payments incrementally: first P2P transfers, then bill payments, then loans."
flowchart LR A["Plan MVP"] --> B["Develop Increment 1"] B --> C["Review Feedback"] C -->|"Improve"| D["Develop Increment 2"] D --> C C --> E["Final Product"]
4. Comparison Tables
Question: "Compare monolithic and microservices architecture." Answer (6 marks):
| Aspect | Monolithic | Microservices |
|---|---|---|
| Definition | Single codebase, tightly coupled | Small, independent services |
| Scalability | Scale entire app (inefficient) | Scale only needed services (e.g., Daraz’s payment service) |
| Deployment | Slow (redeploy entire app) | Fast (deploy individual services) |
| Complexity | Low | High (orchestration needed) |
| Fault Isolation | One crash = whole app down | Isolated failures (e.g., NEPSE’s order service fails, UI still works) |
| Example | eSewa’s early versions | Google’s YouTube (video, comments, recommendations as separate services) |
In the Real World
eSewa’s Scalability Challenge
- Issue: During Dashain, transaction volume spikes 10x, causing 5-second delays.
- Solution: Uses Kubernetes auto-scaling and Redis caching to handle 500K transactions/hour.
- Lesson: Always design for peak loads, not average usage.
Ncell’s Ethical AI Dilemma
- Issue: AI model misclassified rural users as "low-value," leading to poor service.
- Fix: Added human reviewers for <50K loans/year and retrained the model with rural data.
- Lesson: Bias audits are non-negotiable in high-stakes systems.
Daraz’s Technical Debt Crisis
- Issue: Monolithic design caused 3-hour outages during 6.16 sales.
- Fix: Migrated to microservices, reducing downtime to <5 minutes.
- Cost: $1M in development, but saved $5M in lost sales.
NTC’s Legacy System Struggle
- Issue: COBOL-based billing system can’t handle prepaid plans.
- Workaround: Manual patches cost $200K/year.
- Solution: Incremental migration to Java microservices (phased over 3 years).
Khalti’s Privacy vs. Convenience Trade-off
- Issue: Biometric auth speeds up payments but raises privacy concerns.
- Compromise: On-device processing (data never leaves the phone) + GDPR-compliant policies.
- Lesson: Transparency builds trust—Khalti’s user base grew 30% after clarifying data use.
Final Checklist for Exam Readiness
- Memorize definitions: Software issues, technical debt, ethical challenges.
- Know tools: Git, Jenkins, SonarQube, Kubernetes, LoadRunner.
- Practice diagrams: Context models, incremental delivery, CI/CD pipelines.
- Relate to Nepal: eSewa, Daraz, Ncell, NTC, NEPSE examples.
- Understand trade-offs: Scalability vs. cost, ethics vs. convenience.
- Review past papers: Focus on diagram-based and short-answer questions.
Branching strategies (e.g., GitFlow) used in Nepali startups. (Image: TheresNoTime, CC BY-SA 4.0, via Wikimedia Commons)
Based on the TU BIT syllabus for Software Engineering (BIT302), unit 14.
Discussion
Loading…