JavaScript from 2001 on India's largest private bank site
netbanking.hdfcbank.com
netbanking.hdfcbank.com
They restricted the bank from issuing new credit cards for a year which is a big penalty all things considered. Also, they were given a deadline to get their tech stable and they actually brought in an IT provider for the bank to fix things which was bit high handed. But the bank was very big in the country and a failure can have cascading affects which was the reason said by the central governing bank.
I believe it was the first of the kind in the country to penalize a bank because their tech was unstable.
This is hilarious because they are actively offering credit card upgrades all around right now.
For eg, Regalia first -> millenia; which is a flat out downgrade!
[0]: https://www.rbi.org.in/Scripts/FS_PressRelease.aspx?prid=465...
While HDFC's IT systems remain a bit problematic (though not as bad as YES Bank) the bank itself is pretty good. There is a saying in Mumbai that if HDFC is funding your mortgage you dont really have to do due diligence about legality of the property. (It is common in India for a builder to sell the same property to two different people, sell properties with lien and so on).
It remains one of the healthiest banks in India, displaying good growth and trust from consumers.
Also, the lack of good UX in Indian banks’ online banking is truly astonishing. Particularly HDFC, which presumably is rich enough to effort decent UX people.
datestr += '<option value="" selected>-mmm-</option>';
datestr += '<option value="01">Jan</option>';
datestr += '<option value="02">Feb</option>';
datestr += '<option value="03">Mar</option>';
datestr += '<option value="04">Apr</option>';
datestr += '<option value="05">May</option>';
and case "alphanumhyphen":
if(l_str.length >0 && l_str.search("[^A-Za-z0-9\-_]") >= 0 ){
if(p_alertFlg){
alert( p_fldTitle +" should contain Alphabets or Numbers or - or _");
}
return "alphanumhyphen";
}
break;
case "numeric":
if(l_str.length >0 && l_str.search("[^0-9]") >=0 ){
if(p_alertFlg){
alert( p_fldTitle +" should contain Numbers");
}
return "numeric";
}
break;
case "decimal":
if(l_str.length >0 && l_str.search("[^0-9.]") >=0 ){
if(p_alertFlg){
alert( p_fldTitle +" should be Numeric.");
}
return "decimal";
}
break;
What is the correct term to describe this type of code?I used to call it "Spaghetti Code". But I recently learned that it's incorrect. "Spaghetti Code" only refers to programs with messy and unclear control flows (especially unstructured programs that abuse goto), it's not the correct term for code with useless repetitions.
There's a lot to be said for boring, easy to understand code.
I have seen modern JavaScript that can be just as bad as this.
At least it's not a minified blob built up from dozens of repos whose primary purpose is to make its authors look (feel) productive/prolific.
https://en.wikipedia.org/wiki/File:Forgotten_edits_in_copypa...
Now I just want to figure out all of the food analogies for bad code patterns...
I mean if I were to change that option string generator, I could make a numeric for loop from 1 to 12, left-pad a zero for the value, and lookup the month label from a label array or create a Date object and use its formatting options to output the label. I loop over an array of objects with a value and label. With ES6 I could do that with a .map() operation.
It's inelegant but it does what it says on the tin. Can't have an off-by-one error if you don't use loops or indices.
The function is formatted and it does what it suppose to do. It can be refactored to make it less code.
I'm not entirely sure how you came to that conclusion. Lookup tables and format strings have been around for... well, I'd guess almost a century.
- Why not check the length of the string before the switch? - Why return a string which is (meant to be) identical to a variable? - Why not set the regex into a variable and then only have one if-block?
"Don't repeat yourself" is a very good rule for many very good reasons, but a big one is that you don't have to change 10* different places to change 1 thing, which gets rid of a whole class of extremely common bugs. Also, it makes it much more obvious what the code is doing, since your brain only needs to parse 10 different one-line assignments instead of 10 different six-line blocks.
* Replace "10" with whatever the actual number is.
Duplication is never pretty, but when it's as local as here, it's pretty much harmless. Duplication that's not obviously duplication, that's a problem. This is not that.
To answer your question, in 3 places, a few lines apart from one another.
Duplication displays exponential growth.
https://arstechnica.com/tech-policy/2021/02/citibank-just-go...
public static boolean TRUE = true;
I've directly asked if they think TRUE will some day need to be set to false but they just ignore me.
It will happen one day, it will go into production, and the app will work surprisingly well with some subtle glitches. After revealing all contractor devs will make poker face and things will continue as before.
Anyway the big day comes, we turn it on, everything looks good, everyone is happy.
A few weeks later I noticed we forgot to turn one of the flags on. So I asked a teammate what he thought. He shrugged, we figured it would be slightly better to turn it on.
Fun times.
Think the worst one was we had some code that would add a pad in somewhere after the page was rendered that would cause IE6 to redraw the page correctly.
``` if (l_y < 1900 || l_y > 9999) { l_err = 1 ; l_errstring = "Year is invalid."; } ```
Something has gone seriously wrong with human society if that ever actually happens.
Banks are utterly famous for this stuff, and I think the new trend at least here in Australia is to start spin off 'neobanks' that begin with a fresh slate, but are still owned by their parent bank.
A few years back a German/EU law required banks to introduce real 2fa for customer logins and payments. The deadline had to be extended several times and still some banks and merchants missed it.
Multiple reasons:
1) They're banks. Banks are run by the worst type of MBA beancounters you can imagine - all that counts is profits (and the more the better, which is why way too many banks dabble in investment banking aka legalized gambling), and IT doesn't bring in profits, so generally bank IT is only doing the utterly minimal effort that is required to stay in compliance with regulatory demands. As you can imagine, they're pretty much overwhelmed when they get requirements that require overhauls - e.g. the EU mandating overnight SEPA transfers or real-time identity confirmation (PSD2).
2) The tech stacks are comically old and complex (which is the reason for pin-only passwords). The decades-old mainframe stack with hundreds of custom built applications interfacing to it means that even something as innocent as alphanumeric passwords may be all but impossible to do. And don't get me started on Unicode, you're lucky if the base minimum that all connected applications understand is something like ISO-8859.
3) Related to this: as the software is so old, it literally embodies decades of knowledge of all possible kind of "edge cases" and hidden assumptions. Like... developers assume that a dead person stays dead, which is a sane thing to believe since zombies aren't real, but then you have someone declared dead by court reappear alive, and suddenly the workflow breaks down. Or that someone who registered as male can't change their legal gender, or that there are only two genders (which is quite fucking over many many MANY industries who implemented gender as a boolean, e.g. is_female), or that a marriage exclusively consists of husband and wife (changing that one is costing the public sector an awful lot of work, even many years after same-sex marriage got legalized in Germany).
4) Security audits in big companies (not just banks) are just checklists for insurance vendors, no matter if they actually make sense or not. All that matters for the C-level execs is "assuming someone hacks us, will insurance find a way to deny payments?" and not "is this actually secure?".
5) Regulatory agencies are so risk averse it hurts. What they don't know for years is haram - Kubernetes? Cloud hosting? Even proposing that will get you as a developer a shoot-down order from legal, since the regulatory agencies won't certify it.
Source: done a couple jobs involving either interfacing or directly working with medical and banking services.
Many android phones have dual physical SIM cards, so when I travel, I still keep my bank-registered number on roaming.
But I totally agree with your point - of all places, Banks are probably WORST with 2FA. No U2F or even TOTP. There was one bank where I live that offered thise battery powered RSA physical tokens, but they are way worse in practicality.
```
25//2001 Gopi Yedla Changed code for new FD opening
```
Service company that wrote the code has changed it's name from i-flex to Oracle Financials.[2]
Imagine finding the code you wrote today in a random internet discussion in 2040.
[1] https://www.linkedin.com/in/gopiyedla/
[2] https://www.firstpost.com/business/biztech/i-flex-solutions-...
This is like saying that Windows 10 is from 1985. Just because the first version came out then doesn't mean the latest version did.
Also, just because something is old does not make it bad. How old is `mv`?
I can't imagine having some JS I wrote in the early 2000's on the front page of hacker news for the world to see.
Luckily today we have build tools to prevent us showing our dirty laundry in public.
There's a little bit of testing you have to do, because early browser wars resulted in intentionally added incompatibility gotchas, but it's not that bad.
The Web is an amazing and unique platform unlike almost any other available to us. We're so lucky to have it.
I recently ran Netscape 4 for the giggles and +90% of the web no longer functions as I could not load the pages due to the protocols no longer being supported.
You may be testing against JS features but in reality those browsers cannot function on the open internet as their protocol and security stacks aren't supported.
A simple check of caniuse.com is sufficient, but if you're worried here's which browsers are in use https://caniuse.com/usage-table . Netscape no longer even registers.
Because I like them.
Because I believe in Any Browser.
Because of retro-computing.
Because with every known scenario I cover, several more unanticipated ones are also covered.
Also, yes, I can imagine being limited to a particular older version of a browser, NN 2.0 included.
Because it's fun as heck.
Because I'm fucking tired of browser monoculture and I want the Web to be compatible again. If I, one determined developer, can make it work in Mosaic, IE3, Netscape, Opera 3 and 12, Lynx, Links, Dillo, Netsurf, w3m, PaleMoon, Waterfox, Google Translate, and yeah, with some grinding, Chrome, with and without JS, hopefully some devs out there feel embarrassed for their code and try a little harder...
Due to the wide variety of scenarios and configurations I already have tested with, I think it would be more likely than not that I'd be able to complete my base features test script with few issues.
Your question is a perfect example of why I go so far with testing.
Do you mind if I ask what kind of stuff you’re maintaining where you see any traffic from these old browsers? Do you think it would ever be possible to transpile a site into some shared common set of syntax/features/whatever instead of making browser specific corrections? And what do you think about features like WebGL which are impossible to replicate on older browsers in a performant way?
>Do you mind if I ask what kind of stuff you’re maintaining where you see any traffic from these old browsers?
I'm maintaining mostly text-based resources, some of them about technology and interesting to nerds and retro enthusiasts, otheres just general purpose, which I want to make accessible to as many as possible.
For example, when I conducted my first user studies with actual users of screen readers, NO ISSUES were encountered, even though I had not yet made any special adjustments for them.
>Do you think it would ever be possible to transpile a site into some shared common set of syntax/features/whatever instead of making browser specific corrections?
Yes, absolutely. JavaScript makes it very easy by being able to feature-check most things. Also, NoJS is something I already start out with, so it's not difficult to just skip past things like createElement if not supported.
Three biggest challenges I've encountered is no > character (Mosaic treats it as end of HTML comment), no ===, and no anonymous functions.
>And what do you think about features like WebGL which are impossible to replicate on older browsers in a performant way?
I haven't done WebGL, but one feature I have which requires relatively modern JS (think Presto and IE9) is in a separate feature-checked module, older browsers not currently supported.
Again, my goal is for basic feature support, in some cases requiring a skilled operator. For example, this particular feature (client-side cryptographic signatures) can be replicated with an external application.
You need not look far for a great example of progressive enhancement and the benefits it brings. HN has a couple of JS-only niceties, without which the site is still perfectly usable.
I happened upon a great digital art exhibit at the MFA in Boston, and one of the rooms had several beige boxes with Windows 95 and Netscape 3.04Gold set up to exhibit older Web art in a time-accurate setting.
It was then that I realized how much I liked that particular browser, how much I enjoyed using it, and also how capable it was. So I tried to adjust for it, and by then I had tested under so many others, it wasn't even much work. After that came others, like Mosaic and OffByOne and even more obscure stuff, barely a blip on the radar in its day. It became a fun hobby, and something to be proud of.
A couple years ago, NYC had useful Web access kiosks which were than locked up over public outrage about outdoors people using them for porn. However, they allowed Google Translate, and I was able to both read and post to my site via that.
I had not foreseen the use case, but because I had tested for so many others, it worked. All around, I refer to this as the bending over backwards development model. Like the city bus, I work hard to accomodate everyone, and don't turn anyone away if I can help it. Except spammers, fuck them.
https://shkspr.mobi/blog/2021/01/the-unreasonable-effectiven...
> A few years ago I was doing policy research in a housing benefits office in London
> ...a young woman sits on a hard plastic chair ...Clutched in her hands is a games console – a PlayStation Portable.
> ...She’s connected to the complementary WiFi and is browsing the GOV.UK pages on Housing Benefit
> The PSP’s web browser is – charitably – pathetic. It is slow, frequently runs out of memory, and can only open 3 tabs at a time.
> But the GOV.UK pages are written in simple HTML. They are designed to be lightweight and will work even on rubbish browsers. They have to. This is for everyone.
I'm 99% certain that the latter part of that is false. Personally the PSP's browser was about on par with, eh, IE7 or so, the last time I used it (circa 2013).
But heck... it even had Flash.
It takes great skill and effort to do this. Sure its a little batshit, but I applaud the level of perseverance that goes into it. I might have a different view if I was trying to ship something to a specific market segment in a hurry. However I'm not, and it pleases me immensely to see people do such silly[1] (and I mean this with the greatest of respect) things.
[1] For reference, adding chamfers and geneva stripes under things like the main barrel, is utterly silly. However, should I be paying >£50k for a watch, I full expect that _every_ inch of that watch is going to be a masterpiece of finishing (reference: https://www.crownwatchblog.com/how-it-works/finishing-school...)
Many devs are out of touch with the world where people can't afford a new one.
I don't buy the security argument either, it's often just information access which is limited.
Netscape 4 - some minor version - had a bug where if you had a paragraph inside of a list item inside of a div inside of a div it crashed the browser. (I may be misremembering the bug but it was something ridiculous like this)
it was hard to debug for markup that was generated via XSL-T.
So anyway even if the protocols still worked, I don't think you can really expect it to work too much.
Like you, I sometimes take it out for a spin "for the giggles". It's comforting and it works well with my own sites.
I don't worry much about mitm for my purposes, and HTTP still works great, a testament to its design.
Even if we want to support 100% of users and don't think about economics I really doubt there's going to be someone with Netscape 2.0 visiting your website nowadays.
The future is unknown, but I want to be as ready as I can be.
See my other comment for more thoughts.
Do you really? And if so, who cares? (I mean "who as in which webmaster would even care?" not as in, "are there any niche enthusiasts that do?").
When the parent says "is anybody", they mean "are any significant numbers". So, yeah, maybe there is 1. Or 10. Or 100 if we're generous. I doubt there are 1000 (and the website stats can easily verify it), and they surely aren't any number big enough to care about.
But even more importantly, there's no technical, ethical or other rule to say "you need to cater to the person using Netscape 2 in 2021" anymore than there's one saying "You need to sell music in wax cylinders, lest someone who still uses such a player comes to your shop".
If it was an accessibility or poverty argument sure. But it's surely not poverty the reason why someone keeps using Netscape 2.0 in 2021.
To summarize, if I can accomodate that one user, whatever their reasons or situation, which I do not pretend to know, instead of turning them away, then I will invest my time and effort in that.
And where Netscape 2.0 can go, so can probably another browser and configuration I,m not even aware of or anticipating.
I hope so. If it weren't for the ever-increasing bloat, on both webpages and webpage-as-an-app's, it wouldn't be a problem. What can you do today with your computer that you couldn't have done 20 years ago? ("Looks better" doesn't count)
However nowadays, I imagine we're getting maybe 2^3 every 20 years, by the way things are looking. And the baseline is much more capable.
So I wouldn't be too shocked if a desktop from 2021 is still usable in 2041. I was occasionally using a desktop from 2009 until 2019, and it was ok for web browsing, movie watching, editing some documents, etc.
There is no way anyone is viewing your page in anything older than IE 10. If you're in some niche market or region maybe IE 8.
I believe in Any Browser.
My other reply explains my reasoning.
My niche sites see all kinds of browsers, btw.
Currently developed browsers also include Links, Lynx, Dillo, Netsurf, and w3m.
Have you thought about creating a library for this? It could be used for progressive enhancement on sites that would normally have no JS.
All the JS modules are also optional, and can be turned off with one setting.
It is not production ready yet, but demos and code can be accessed via my profile.
No part of this work may be reproduced, stored in a
retrieval system, adopted or transmitted in any form or by any means,
electronic, mechanical, photographic, graphic, optic recording or otherwise,
translated in any language or computer language, without the prior written
permission of i-flex Solutions Limited.
This language would seem to make it legally awkward to even visit the web site, much less have this discussion.... to be honest I think that while it was one of the worst dependencies, it was still ages beyond the code they wrote themselves ¯\_(ツ)_/¯
Not 3 1/2", not 5 1/4"... 8 inches.
https://www.cnet.com/news/us-military-retires-floppy-disks-u...
Lockheed-Martin happily sold what I described as fresh development in 2012. EDIT: And unlike the system with 8" floppies, it never worked and resulted in 5 years of extra sunk costs til the whole critical system got yeeted and things were started from scratch.
In comparison, the new and wonderful system from Lockheed that I mentioned? It pretty sure never ran in "production environment" properly, and I shudder to think how much it and its knock-on effects cost.
It's arguably a waste of time, but it does it always seems like a fun challenge. I'm sure I'm not alone in this.
Is there a more constructive use of that time, while getting the same dopamine hit? I suppose the obvious answer is freelance markets, but I doubt many people are paying out for "just" refactoring.
Banks are innovating in traditional banking. They make fancier branches and better ATM machines, but they fail to innovate in software space while their customers are increasingly using more digital interfaces. And that's how they can't compete with modern FinTech players when it comes to development pace. They are just suck at software and they are lots of middle managers that unintentionally make it even harder.
It’s a sign of the attitude of the programmers and probably reflects the quality of the actual business logic code as well.
function returnFalse () {return false}
and the fact that their home cooked date_val() function does not use their home cooked isLeapYear() and daysInMonth() functions, but uses its own, pretty much unreadable, leap year determination algorithm. var l_k=parseInt(l_y%100)
var l_m=parseInt(l_y/100)
if (l_d == 29 && ((l_y/4)!=parseInt(l_y/4)))
{
l_err=1 ;
l_errstring = "Date is invalid.";
}
if(l_k ==0){
if (l_d == 29 && ((l_m/4)!=parseInt(l_m/4)))
{
l_err=1 ;
l_errstring = "Date is invalid.";
}
}Nothing wrong with the code per se - a little formatting and nicer variable names would make it entirely readable. Having the entire logic inline might be intentional so you can cross-check (legal) requirements and avoid transitive dependencies - the handling of dates specified might not necessarily match what’s “technically correct” at all times. Anyone writing Go will be familiar with this style.
I am surprised to see their js based encryption code.
https://netbanking.hdfcbank.com/jsdir/des.js
function cancel_request ()
{
window.history.back();
return false;
}
—-What?
So, not exactly 2001.
But considering no date libraries were used and all browsers are covered, this is nice code.
To me the new array() is a bit odd, was var array = [] not available yet?
prototypeThese are the "star" private banks, let's not get into the state of public banks.
I have been under serious troubles in past because a Bank randomly blocked my ATM card & UPI.
Start replacing the global variables with ‘const one = useState(1)’, and get a few of those DOM elements into a render function, and it’ll start to look like what most front end people write now days. Split the helper/utility methods out to a helpers.js file, import in the ones you need. Swap out the Date and Number handling with native methods or decent library.
I’d call this person crazy if he abstracted into something wholesale unnecessary like a state machine or a pub/sub pattern, or factory pattern, etc.
So far so good, plenty to work with here. The person was not given any bad ideas to even contemplate writing it in anything but a straightforward way.