Automation Archives - Simple Programmer https://simpleprogrammer.com/category/testing/automation/ Sun, 28 Aug 2022 15:05:27 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 Understanding Post-Covid Automation and Artificial Intelligence https://simpleprogrammer.com/understanding-post-covid-automation/ Wed, 03 Aug 2022 14:00:32 +0000 https://simpleprogrammer.com/?p=41280 In the space of a few days, the world went from functioning as we’ve always known into a global shutdown. Businesses were forced to adapt to this change, and quickly. For many, this meant dealing with a remote workforce for the first time. It’s fair to say that the Covid pandemic caused a lot of...

The post Understanding Post-Covid Automation and Artificial Intelligence appeared first on Simple Programmer.

]]>
post-covid automationIn the space of a few days, the world went from functioning as we’ve always known into a global shutdown. Businesses were forced to adapt to this change, and quickly. For many, this meant dealing with a remote workforce for the first time. It’s fair to say that the Covid pandemic caused a lot of turbulence for businesses.

But it was more than simply the logistics of working locations; general processes also ran into trouble. This meant disruptions to supply chains, cybersecurity, and much more. Systems were exposed, and many businesses struggled to keep up. Suddenly, organizations needed to deploy automated systems to stay afloat.

The truth is, this change was inevitable. Pre-Covid, we had already seen a push toward artificial intelligence-powered robotic process automation. The pandemic only hyper-accelerated this change. The businesses able to adapt the quickest were those that had already taken steps toward automation.

If you’re new to the world of automation, you might be wondering what robotic process automation is, or maybe you’re looking to grow your understanding. Well, let’s start here: What exactly is the process of automation?

What Is Robotic Process Automation?

Robotic process automation (widely known as RPA) is a form of automation unlike any other. Whereas automation relies entirely on coding, a process that has preset outcomes, RPA uses artificial intelligence (AI) to complete tasks more autonomously. AI has had a bad rap in the mind of the public—largely thanks to pop culture—but it isn’t a terrifying machine coming to take over the world (at least, not yet!).

Artificial intelligence, in short, is when a machine tries to mimic human thought patterns to complete certain tasks. In today’s world, this technology is found everywhere, from self-driving cars to race recognition technology.

RPA uses AI to process tasks, removing the element of human error. Think about all the different processes in your business. Each will probably need the oversight of an experienced worker. If, for whatever reason, a worker is unable to activate a process, your business could grind to a halt.

Not only does AI keep your business running efficiently, but it can also provide data-based insights, helping to improve processes. Organizations that have adopted RPA have seen improvements across the board. This includes improved compliance (92%), improved quality/accuracy (90%), improved productivity (86%), and cost reduction (59%).

How Automation Is Transforming the Workplace

Some form of automation is present in practically every modern business and there’s a good chance your organization might have invested in some of the following forms:

Sales: When you make a sale, it’s unlikely that you’ll process the order yourself. The majority of organizations have a system in place to process and track orders. It’s always a good idea to run crowd testing to make sure your store functions as it should.

Customer Service: An increasing number of businesses are turning to automated chatbots to deal with certain queries. This helps keep your phone lines less busy and means that agents can focus on more difficult queries. Also, VoIP software, such as Vonage or one of these Vonage competitors, is another excellent use of AI in the workplace.

Website: Your website likely contains several automated elements. This could include a contact form, mailing list sign-up, or downloadable files. For all these different elements to operate smoothly, you need the right support (from AI!).

If interested in learning more on how AI powered automation is transforming the workplace, check out Intelligent Automation Simplified by Debanjana Dasgupta, which provides some fantastic insights.

What Does RPA Mean for My Business?

Put into action, AI-powered automation can affect almost every aspect of your organization. Let’s look at some of the benefits of the technology, and why it might be time to revamp the automation within your business.

Speed Up Processes and Slash Costs

With RPA, data can be copied into a spreadsheet in a matter of seconds, and with a much-reduced risk of (human) error occurring during data entry. The decrease in time and error are reasons enough to see the value of AI.

Think about the difficulties of handling manual processes. You’re probably collecting a large amount of data. Even after carrying out process mapping, data can be difficult to keep up with since information needs to be stored properly so it can be accessed later.

There are two significant issues with properly storing data. First, there’s a time factor to consider. Your employee is entering each piece of data manually, and the scale of data means that this task could take an unknown amount of time. Second, it only takes one slight error for your data to be rendered useless unless more time is spent trying to find a correction.

Remember, the faster data is added to the database, the quicker it can be used to improve your business. For example, this might mean new and inventive forms of marketing. Or it could be used to help show how to improve product quality.

Additionally, RPA can be a great way to reduce costs. With an automated system, you’ll need to employ fewer people, saving you some cash. The workers you do employ can move away from data entry and put their skills toward other valuable tasks that can help you grow your business.

Stay On the Right Side of the Law

Another aspect of properly handling data is the legal side. Today, people are much more aware of their data and how it’s being used, and this has brought about new legislation to regulate the ways businesses can collect and handle data.

Many of the new laws come with painful fines attached. For example, the EU’s General Data Protection Regulation (more commonly known as GDPR) sets fines of up to €20 million. It’s fair to say that most penalties won’t reach anywhere near this number, but it does show how seriously the issue is being treated.

These new laws pose challenges for many businesses—big or small. To reduce the risk of breaching legislation, it’s better to limit data access to as small a number of employees as possible. Again, this is where RPA can come in handy. Because processes are automated, there’s a limited need for human oversight.

More Secure Data

The idea of data leaks is becoming an increasing concern for many businesses. According to a recent report, small to medium-sized businesses are hit by a cyberattack every six months. Similarly, contracting a computer bug can be extremely damaging to your data.

The less secure your data is, the more damage will be done to your reputation.

Some people have expressed concern about RPA and how easy the system may be to exploit. But this concern is largely ill-founded, and it’s your responsibility to show customers their information is safe in your hands. Most modern RPA tools come with end-to-end encryption, meaning your data is extremely secure.

Important note: Do proficient research to make sure the RPA solution you choose comes with the right security features for your company. 

Provide Better Customer Support

Customer support is a lifeline for businesses. If you get something wrong, your support line is your best chance to stay on good terms with a customer. But handling customer support isn’t easy. Many businesses suffer for their lack of attention when it comes to valuing customer support.  

You need to make customer support a priority. There’s a good chance that you’ve experienced frustration when an organization misses the mark on your support. This usually means long hours stuck waiting in queues, only to find that your query isn’t resolved. The average customer feels the same frustration.

One of the main reasons that customer support is slow is that staff are bogged down in admin tasks. Although obviously important, these jobs are repetitive and often take up a lot of time (especially if careful attention is needed, as with data entry).

With RPA, you can automate these tasks so they don’t consume your employee’s valuable time with otherwise delegated responsibilities and allot more time to customer support. In other words, shorter queues and more query help!

It’s important you learn how to calculate CSAT to see if customers are responding positively to changes that you make.

For additional help overcoming common issues with customer support, check out The Customer Support Handbook by Sarah Hatter.

Engage with Data

Data is king in the modern world. With the right data, we can improve every aspect of our organization. This could involve improving workflows, creating better marketing, or making a more engaging website. But first you need to gather the right data. You’ll also need the right analytics software to unpack data into usable information for your business.

RPA operates on a constant feed of data, and you can learn from this information in a multitude of ways. For example, you can put RPA data into a machine learning algorithm, which can be used to spot issues with your processes and suggest steps toward optimization. This way, you can boost the overall efficiency of your organization.

Better Email Automation

Email can be a great way of staying in touch with customers—most businesses use email for marketing. With an email referral program, you can even grow your customer base.

But sending all emails manually isn’t practical. For this reason, almost every business uses some form of email automation. This ensures customers receive regular communications and reduces the workload for your staff. But could this automation be improved upon?

There are several ways RPA can help your email automation. While other automation tools require you to write lines of code, RPA does not. It has been specifically designed to be integrated quickly and easily without any previous programming experience.

This means your RPA can get to work scheduling your emails, validating email addresses, and cleaning up your email list.

It can also be adapted and modified to suit your changing email needs without having to employ an experienced programmer. Not only do you save money, but you also have the flexibility to make modifications to your email campaigns as needed.

Improve Admin

No one enjoys doing administrative work, but it’s a necessary evil. RPA can make this irritation a thing of the past, dealing with menial tasks and letting staff focus on more important matters.

It can, for example, complete data entry for invoice processing, help onboard new employees, and support the payroll process from start to finish by checking time records and generating paychecks. It can also help with accounts reconciliation, placing sales orders and keeping customer information updated.

You can use RPA alongside other tools to further help with admin, too. For example, a free online contract generator can help reduce the amount of time spent building contracts. There really is no end to the ways RPA can support your team.

Will This Affect the Number of Workers I Need?

You might be thinking that with the rise of AI, you won’t need staff at all. But this isn’t quite the case. Bringing automation into your organization will reduce the number of manual tasks that you’ll need to complete—say goodbye to time-consuming data entry, basic customer service, and emails! This will inevitably mean a smaller number of staff is needed. But effective automation needs a knowledgeable workforce to go alongside it.

AI has limitations and is far from reaching its full potential—there are tasks that go beyond the skill set of AI. Meaning, you’ll need employees with the right skills if these tasks are to be completed effectively. Similarly, while AI may be able to learn, you won’t be able to assign it an innovation challenge since it can’t think creatively.

Used in tandem, a strong workforce alongside the right RPA technology can make a strong team.

Will My Workforce Need to Change?

Automation is the future. Whichever way you look at it, the world is changing. But as technologies change, so must employees. This isn’t unusual. Look at the world 30 years ago compared to now: technology has changed dramatically, and workers now have different skills to complete tasks.

Looking to the future, this kind of change will need to happen again. Your existing staff will need time and training to adjust to new technology. Staff will need to be capable of working with AI-powered systems from the back end.

For example, this could involve learning to work with drones when handling the supply chain. They also need to know how to test automation metrics to ensure systems are working correctly.

You should also consider the skills you look for in new employees. These, too, will need to change if you’re to find the right people. It’s always good to introduce people who already have experience working with AI so they can share their expertise with their teammates.

Start Preparing Now

The change to automation is well underway. It’s understandable if this change seems daunting; new systems and procedures can be difficult to get your head around. There’s no doubt, however, that automation can give your business a boost.

As we’ve explored here, there isn’t really an aspect of your business that wouldn’t benefit from automation. From HR to finance, and customer service to marketing, RPA can revolutionize the way you do business and make life easier for your employees. But, remember to take your time when introducing new systems and really evaluate which areas of your business would benefit most. Review each department carefully and make sure that you carry out automation testing to ensure that it’s working as it should be.

Of course, change needs to start from the bottom up. Your staff will also need support to adapt. Make sure you give time for training, and that your employees know it’s okay to ask questions.

So, start preparing now and embrace the future today!

The post Understanding Post-Covid Automation and Artificial Intelligence appeared first on Simple Programmer.

]]>
9 Mistakes Most Automation Testers Make (But You Don’t Have To) https://simpleprogrammer.com/9-mistakes-automation-testers-make/ Mon, 26 Oct 2020 14:00:18 +0000 https://simpleprogrammer.com/?p=37376 If you have decided to become an automation tester, you’re bound to make mistakes, especially if you are doing complex automation testing. If you want to avoid errors and become proficient in automation testing faster, learn from others’ mistakes. With that in mind, below are nine common mistakes that most automation testers make, but you...

The post 9 Mistakes Most Automation Testers Make (But You Don’t Have To) appeared first on Simple Programmer.

]]>
mistakes automation testers makeIf you have decided to become an automation tester, you’re bound to make mistakes, especially if you are doing complex automation testing. If you want to avoid errors and become proficient in automation testing faster, learn from others’ mistakes. With that in mind, below are nine common mistakes that most automation testers make, but you don’t have to.

Before we start, remember that 100% automation is a myth, and we always need manual testers.

1. Automating Everything

My first assignment was to automate Selenium test scripts for a web application. To impress my mentor, I picked up another module as well, and in a few days I hit a wall.

It turned out that that module was not meant to be automated, as it could cause many false positives and negatives. It cost me time and reputation. So much for my first impression, I would say.

Always define the scope of the tests first, then think about automation. As a new automation tester, we want to test everything. You may automate 95% of the project, but will that be worth the time, effort, and money? It’s crucial to be curious, but always remember that automation is not a magic wand, and it is not possible to automate everything.

Always ask yourself why you need to automate a particular project. Ask more experienced colleagues. If they think it offers real benefit, then take it as a green light. Automate only those tests that provide value and save resources.

Tip: Automate when it is necessary; don’t automate just for the sake of it.

 2. Not Paying Attention to Tools

Tools can make testing easy or challenging, so choose them wisely. You will need to be clear about your objectives so that you can choose your tools accordingly. Different tools can help you achieve different goals.

For example, if you want to test API for a website, you should choose Postman; if you’re going to check your website’s cross-browser compatibility, go with a tool like LambdaTest. A project can be divided into many objectives, and we can achieve each objective using different tools.

Tip: First find the problem, then find the tool to solve it—not the other way around.

3. Not Coordinating with Fellow Testers

It is highly likely that as a new tester, you will be working on a team. Typically, a team has people with different levels of expertise. Knowing your fellow testers better will help you understand who is doing what and who is good with what—so you can reach out to them accordingly.

By knowing them and their skill set better, you can save time when you encounter a problem as you know to whom to reach out. Also, it’ll reduce the chances of random task allocation.

Tip: Know your fellow testers well before you start testing.

4. Not Keeping a Check on the Resources

Testing is a costly process. But most of the time, people forget about these costs. Remember: a tester’s salary is not the only cost for the testing process. Tools, infrastructure, machines, training, and up-gradation are also expenses.

If you are using an open source framework like Selenium for cross-browser testing, testers must be trained on the framework. Sometimes they need the tools for upscaling the testing. For cross browser testing, automation tests on a local machine may not be enough for a growing company; your team may need cloud-based parallel testing infrastructure.

The team may need some training for the tools, like cross browser testing tools, or subscriptions to third-party cloud services, like web hosting. All these will be expenses, even before the process of testing starts. By using all the resources with maximum productivity in mind from the early stage of your career, you will be able to impact positively on ROI of the resources.

Tip: To become an asset for your team, you need to understand the liabilities first.

5. Focusing Only on Codeless Automation

If you want to get the job done quickly, codeless automation is an easy escape, but it won’t help you develop your skills. If you go to an interview with only this skill, you will have a hard time cracking it.

Software and websites are becoming so complicated that it is nearly impossible to automate everything using codeless automation tools. So, you mustn’t run away from code.

Tip: Do not use codeless automation before you know how to write the test code. 

6. Not Paying Attention to the Test Design Process

Test design is used to build tangible test cases from general use, observations, and objectives.

As a newbie, I used to undermine the process of test design by directly jumping to the automation script writing. Test design was a boring task to me, and I think that was my biggest mistake, because I never had a full picture of the end result I wanted. It led to many retrospective corrections and time waste.

Designing the test will help you to create real-world applicable and meaningful tests. This will give you an overall idea before you write the first line of the code and make the testing process extremely efficient for you.

Tip: Do the work right the first time so you don’t need to waste resources to fix it.

7. Falling in the Trap of False Positive and Negatives

A false negative is when test results wrongly indicate that the test failed, despite passing. A false positive is vice versa.

The test report is not the universal truth, and we need to take it with a grain of salt. For example, if you are testing the login functionality and the report says the user successfully logged in, you better go and check if the user actually logged in or not. Making mistakes with these types of things can hurt your credibility as a tester.

Tip: Test your testing code first and then test other’s code

8. Not Following the Ground-Up Approach

Take one step at a time, and start with baby steps. The ground-up approach dictates that you start by automating the tests for smaller modules, and then climb to the bigger modules.

As a newbie, you might not know about all of the outbound and inbound processes involved. You may lack the skills to write tests for bigger modules and end up with nothing to show after days of work. So, always start small and build your skills from there.

Tip: Starting small will prepare you for bigger modules.

9. Not Performing Exploratory Testing

mistakes automation testers makeOne of the common mistakes most automation testers make is not incorporating exploratory testing into their weekly routine—I have done it too. Don’t fall into the trap of looking at scripts and pre-written tests only.

With exploratory testing, you can figure out new test cases that may not be in the pre-written tests. So, don’t forget to perform exploratory testing periodically.

Tip: Don’t forget to explore.

Right on Time to Become an Automation Tester

Right now is the best time to hop on the bandwagon of automation testing. Almost all the major frameworks are either available with automation or moving in the direction of automation.

When you step into the world of automation testing, you are bound to commit a few mistakes. However, following the above tips will ensure that you avoid the major ones.

The post 9 Mistakes Most Automation Testers Make (But You Don’t Have To) appeared first on Simple Programmer.

]]>
Enhance Your e-Commerce Development With Web Test Automation https://simpleprogrammer.com/e-commerce-development-web-test-automation/ Mon, 28 Sep 2020 14:00:21 +0000 https://simpleprogrammer.com/?p=37146 Сompetition in the e-commerce market is growing by leaps and bounds. So if you want to stand out from the crowd, build your online shop with users in mind. To make sure you address the most burning client needs in terms of usability, accessibility, functionality, and security, take your e-commerce store development to the next...

The post Enhance Your e-Commerce Development With Web Test Automation appeared first on Simple Programmer.

]]>
web test automationСompetition in the e-commerce market is growing by leaps and bounds. So if you want to stand out from the crowd, build your online shop with users in mind.

To make sure you address the most burning client needs in terms of usability, accessibility, functionality, and security, take your e-commerce store development to the next level with web testing automation. With automation, you not only perform testing in a 100% consistent manner by eliminating manual error, but you also accelerate time to market for your e-commerce product without sacrificing quality.

Also, QA automation will help you optimize development costs. Namely, you can run automated tests simultaneously across multiple devices, platforms, and browsers as many times as needed — without the need to pay for manual testing over and over again.

Here are some ways that you can use web test automation in your e-commerce development to improve user experience and save on time and effort.

Improve Website Look and Feel

You never know what device and browser consumers will use to make a purchase, so be ready to provide comfort whatever the case.

Make the most of automated cross-device compatibility testing to adapt your UI to a wide range of resolutions, screen orientations, operating systems, mobile network events, and more. Run automated cross-browser tests in parallel across a huge number of real browsers and their configurations to find and timely eliminate bugs.

Also, leverage automation around UI regression tests to make sure that after any major debugging, window controls like buttons, toolbars, and menus are well-organized and meaningfully labeled, spelling and grammar are localized, and style and color in links, backgrounds, and fonts are consistent.

Ensure e-Store Accessibility

At the moment, about 650 million people on the globe live with a disability, making up 10% of the world’s population. Did you take this information into account when developing your online shop?

Web accessibility testing will help you make sure your solution complies with accessibility standards — in turn, people with auditory, speech, visual, and other disabilities can easily shop on your website.

With robust web test automation in place, you’ll be able to optimize your e-store in terms of readability and navigation. That usually means:

  • Using the optimal combination of text color, background color, and text size.
  • Avoiding complicated copy.
  • Adding detailed image descriptions.
  • Enabling screen reader and voice commands.
  • Ensuring robust keyboard navigation.

While accessibility testing automation is crucial, don’t underestimate the power of live user testing. By getting real shoppers with disabilities to check out your online store, you’ll get on the frontline of Web Content Accessibility Guidelines (WCAG) compliance.

Perform Critical Path Testing

You can also use automated usability testing to make sure all key functions of your e-commerce system go off without a hitch. For example, customers should be spared difficulties in ordering items — the size, color, and the number of products in the shopping cart should correspond to the client’s request.

When implemented correctly, web test automation will also help you thoroughly check the accuracy of financial transactions, including payment gateway choice, verification code check, order confirmation via email, and delivery method.

According to Nextiva, 89% of clients tend to switch to a competitor after a poor customer experience. To be among the go-to businesses, meticulously examine the customer support functionality with automated functional testing. Namely, make sure shoppers get an instant reply to their queries about the products whether it’s a human-to-human interaction or a chat with a smart robotic assistant.

Safeguard Client Data

To cement customer loyalty to your brand, make your e-commerce solution a secure place to go. Use best-of-breed Open Web Application Security Project (OWASP) testing tools to successfully fight against both known and unknown vulnerabilities.

Automated security testing will help you fully comply with PCI DSS, GDPR, and other industry-leading security standards — keeping customer data out of the wrong hands. Namely, you’ll be able to detect and timely address errors and slight inconsistencies in firewall configurations, end-to-end data encryption, network monitoring, and more.

Also, tap into the power of web test automation to check the robustness of your system’s access management. Specifically, make sure you have a rock-solid access control and two-factor authentication (including biometric-based access).

Test Automation Brings Immediate Value — Go for It

Besides saving you time and effort as compared to manual testing, automated web tests have the potential to notably improve your e-commerce solution’s quality by optimizing website navigation across browsers and devices, enabling accessibility, perfecting all functions, and ensuring rock-solid security.

And great system functioning will guarantee more happy clients, more sales, and, as a result, more money in the bank.

The post Enhance Your e-Commerce Development With Web Test Automation appeared first on Simple Programmer.

]]>
A Guide to Python Programming for Cybersecurity https://simpleprogrammer.com/python-programming-for-cybersecurity/ Fri, 28 Aug 2020 14:00:34 +0000 https://simpleprogrammer.com/?p=36993 Cybersecurity is the practice of protecting networks, systems, and programs from digital attacks. It is estimated to be an industry worth $112 billion in 2019, with an estimated 3.5 million unfilled jobs by 2021. Many programming languages are used to perform everyday tasks related to cybersecurity, but one of them has emerged as the industry...

The post A Guide to Python Programming for Cybersecurity appeared first on Simple Programmer.

]]>
Cybersecurity is the practice of protecting networks, systems, and programs from digital attacks. It is estimated to be an industry worth $112 billion in 2019, with an estimated 3.5 million unfilled jobs by 2021.

Many programming languages are used to perform everyday tasks related to cybersecurity, but one of them has emerged as the industry standard: Python, which is dominating the cybersecurity industry.

Python has a syntax that is easy to read and understand and a wide range of applications that make it a very versatile programming language for any aspiring cybersecurity professional.

Python’s growth over the last few years has been incredible, and it’s now considered one of the most popular languages across all industries, according to Stack Overflow.

python programming cybersecurity

If you’re a programmer thinking of transitioning to security, this post will show you how you can use your existing skill set in another high-income, low-unemployment industry. You could do that, for instance, by either automating repetitive processes to save your team countless hours or by creating security tools that can be used to test the security of applications or systems.

Imperva, a leading cybersecurity software and service provider, reports 77% of the websites they protect were attacked by a Python-based tool. As security professionals, part of our job is to mimic real-life attacks to ensure that companies are ready when real attacks occur, understanding the language and libraries used in real attacks. Replication of those tools is a very valuable skill set.

However, not all Python experience is equal in the security field. To build an effective portfolio, develop effective software, and properly demonstrate your value, you need to focus on learning the right Python libraries and frameworks for the industry.

So let’s look at some of the different Python libraries that you need to know to thrive in these areas.

Automation Tools

Firstly, you want to be able to write effective Python scripts to automate many of the day-to-day tasks of a security professional.

Python has been widely used in security work because of its easy-to-learn syntax and wide range of libraries, which give it a lot of functionality. While other languages can be used to perform these tasks, I recommend learning Python. That’s what the majority of the industry will be using, and collaboration is important.

Many security tasks require you to apply the same operation across hundreds or thousands of endpoints. For example, let’s look at configuration management. This is the practice of defining a secure template for a system, including things like what services are allowed to be on the machine, what ports will be open, firewall rules, etc.

The ability to automate these processes will not only reduce time but also errors. Up to 90% of security incidents are a direct result of human error. The more you can move away from relying on human actors, the better it is from a security perspective. So this leads to the question, how can I learn to automate processes like this?

Boto3

Boto3 is the Amazon Web Services (AWS) Software Development Kit (SDK) for Python, which allows programmers to write scripts that can interact with AWS services like Amazon Simple Storage Service(S3), Amazon Elastic Compute Cloud(EC2), and Amazon Virtual Private Cloud(VPC).

With Boto3 you can start and stop servers on demand, cancel instances that do not conform to your organization’s security standards, perform updates and patch management, and much more. Being familiar with this SDK is very valuable for any professional working with AWS.

Regex

Regex stands for regular expressions, and this is a tool that allows you to search for specific patterns within a block of text. This is a very useful function for extracting information from log files during an investigation or when scraping information from the internet.

By combining this library with other standard Python libraries, you can create some very useful programs. For example, you can use regex to search log files and locate IP addresses so you can determine if someone was able to hack into your network, what actions they performed, and what time this event took place.

Pyautogui and Web Browser

Pyautogui allows your scripts to control mouse and keyboard functions, letting you imitate intelligent user behavior. The web browser module allows you to launch a new browser to a specified URL.

You can use these in programs to automate any action requiring you to go to a website and perform any function, such as filling out a web form, downloading files, etc. This can be used to automate functions that require you to login to a web page and post information.

For example I’ve seen a Python script that automates the process of testing web pages for XSS scripting vulnerabilities. XSS is a cyberattack that tries to insert javascript code into an input form and have that code run on the website.

These libraries can also be used to automate other routine tasks that require you to login, go to a web browser, and perform an action on the webpage.

Pyperclip

python programming cybersecurityThis library gives you the ability to access the clipboard directly from your Python scripts. While this can be done with the pyautogui library, pyperclip makes this process much simpler and adds flexibility to your scripts.

It’s particularly useful for any scripts that involve large bodies of text. For example, say you’re scanning an entire pdf for names, addresses, and phone numbers. Just by highlighting the pdf text and copying it to clipboard, pyperclip allows you to use it in your script as an input, saving you a significant amount of time.

Faker

This library is dedicated to producing fake data that can be used to test your programs. This is important to ensure that whatever scripts or tools you write will be able to perform the action as intended.

For example, if you have a script that extracts URLs, you may want to generate some fake text containing that information and test your program to ensure that your script can find it effectively. Faker can generate random data such as names, addresses, emails, countries, text, urls, etc.

Pen Testing

Another important application of Python programming in cybersecurity is in the area of penetration testing. A penetration test is the process of trying to hack into a website, application, device, or network in order to test the security of that entity.

In order to perform these tests effectively, many professionals create their own tools and scripts that function exactly as they need them to for the test, and this is where knowing Python becomes very useful.

Python is largely used in this area to develop custom scripts and tools used to perform the attacks. If you want to be successful in this area, knowing how to write effective scripts and how to read and understand tools written by others will be very valuable to you. Here are some of the key libraries you need to be familiar with.

Python Nmap

Nmap is a very widely used port scanner. Port scanning is the process of checking what ports are open on a computer and what services are running on that machine so you can start to determine how that machine may be vulnerable to getting hacked.

The Python Nmap library makes it easy for you to utilize nmap functionality through your Python scripts, speeding up the process of scanning a target computer for vulnerabilities and giving you more customization in your scans. This library allows you to analyse nmap scan results, perform custom scans, and import nmap results into other tools.

Socket

Socket is a low-level network interfacing library that allows you to establish client-server connections. In the context of cybersecurity, this is important because it allows you to connect to any machine on a specified port, with a specific protocol, and send data to that machine.

This can be used for port scanning of a machine as well as sending data to or extracting information from a machine. Data exfiltration occurs at a later stage of pen testing and is known as exploitation. Any project that requires you to communicate over a network interface will likely use Socket.

Scapy

Scapy is a packet manipulation library that can forge and decode packets across many different network protocols.

In cybersecurity, there are situations where you need to monitor the packets being sent across a computer network. It could be to determine if someone hacked into your environment, see what ports and services are running on a machine, or troubleshoot a network problem.

Whatever the reason, this library is great for performing packet analysis and can allow the same functionality as popular tools such as Nmap, Wireshark and tcpdump.

Requests

Requests is pretty self-explanatory. It allows programmers to send HTTP requests through their scripts. HTTP requests are useful for pen testing activities by allowing the creation of custom payloads and attacks against web applications.

Requests can achieve the same functionality as a tool like burp suite but with more customization to your needs. Imperva researchers found that Requests was the most popular Python library used in web-based attacks, used in 89% of Python-based attacks.

Beautiful Soup

This library specializes in assisting the information-gathering phase of penetration testing.

Beautiful Soup allows you to parse data from HTML and XML files, letting you automate data-scraping tasks. Data scraping can be important during the open-source intelligence phase of a penetration test, as this phase is dedicated to finding as much information about the target of the test as possible.

For this reason, you may want to create scripts to automate this phase, searching in places like Github to find information on your target company. This information could include IP addresses, or User IDs and passwords that are often accidentally committed by developers to public repositories.

Additional Resources

python programming cybersecurityEach of these libraries adds important functionality, but to get proficient with writing scripts related to security, it’s best to learn them in a structured way.

When it comes to automation tools, I highly recommend these two resources because they cover all of the core Python libraries used in automation of everyday tasks, and they guide you through several projects that you can put in your portfolio to demonstrate your knowledge to a recruiter.

  • Automatetheboringstuff.com: This free ebook walks you through all of these libraries and more, related to automating everyday work tasks using Python. It is by far the most comprehensive guide I’ve found and comes with practice exercises, projects, and walkthroughs.
  • Google’s Automation with Python Professional Certificate: Google has a crash course to introduce you to the language and walks you through important aspects of automation for an IT professional.

As you’re learning Python, I would highly recommend you keep all of the code that you write in these courses and use it in a portfolio. An easy and free way to do this is through a Github portfolio.

Each of these courses comes with several practice project ideas that you can do, but some of the key skills you want to demonstrate are the ability to read and write to files, extract information from text, and interact with online services through Application Programming Interfaces (APIs).

If you’re interested in learning Python directly for pen testing, here are some good places to start. These books go into great detail on how to use Python to accomplish security-specific activities, like security automation, developing Python security tools for security testing, and Python scripts used in computer forensic activities. They are also well respected by the security community, which is a testament to their quality.

  • Violent Python: A Cookbook for Hackers, Forensic Analysts, Penetration Testers and Security Engineers

The ability to program is a valuable asset for any aspiring security professional, especially if you’re interested in technical roles such as being a security engineer or penetration tester.

Python Is Crucial in Cybersecurity

Python is the most prevalent programming language in cybersecurity, and demonstrating your ability to program in this language can greatly improve your chances of landing a job.

For building a strong programming portfolio, you want to focus on demonstrating that you can automate everyday tasks with Python as well as create security tools for Pen Testing Web Applications, Networks, and Computer Systems.

Cybersecurity is one of the highest paying tech industries, and it’s only projected to grow, presenting a big opportunity for those who are qualified.

The post A Guide to Python Programming for Cybersecurity appeared first on Simple Programmer.

]]>
5 Reasons Coders Should Incorporate a CI/CD Program https://simpleprogrammer.com/coders-incorporate-ci-cd-program/ Mon, 06 Jul 2020 14:00:07 +0000 https://simpleprogrammer.com/?p=36683 Coding can be tedious and difficult at times. Getting as much help as you can is a good idea, which is why using a CI/CD tool is a great assistant to help with your project. Using a CI/CD tool can really increase your value as a programmer and can be a great addition to your...

The post 5 Reasons Coders Should Incorporate a CI/CD Program appeared first on Simple Programmer.

]]>
Coding can be tedious and difficult at times. Getting as much help as you can is a good idea, which is why using a CI/CD tool is a great assistant to help with your project. Using a CI/CD tool can really increase your value as a programmer and can be a great addition to your development life.

A high-quality CI/CD tool allows for maximum efficiency. It can give you the ability to significantly increase productivity and save noticeable cost. Moreover, it can help you streamline your process for getting error-free software in the hands of your end users.

CI/CD aids in automation as well as making life easier by continuously integrating code and continuously deploying code—hence the name. It makes catching errors easier, while enhancing communication and code integration between co-workers.

CI/CD program

CI/CD in Depth

has its own benefits independent of continuous deployment (CD). With CI, it’s easy to make small changes frequently with minimal errors, resulting in a reliable product. The changes are able to be seamlessly integrated into all areas of the program, resulting in significantly increased coding efficiency.

CD is the other half of the CI/CD program and refers to either continuous deployment or continuous delivery, but usually continuous deployment due to their differences in automation. This part of the tool allows software programs and any additional changes to be automatically deployed to the end user much more quickly.

Continuous delivery automates the entire software release process and allows anyone with permissions to deploy a new release. It also provides the means to update all areas of the systems and set rules for reactions by other programs and systems. This allows deployment to occur with minimal interruption or conflicts with other systems.

Continuous deployment automates this process by pushing every change in the source code into production instead of having to deploy the new release manually. This makes it a step above the continuous delivery system, saving time overall by eliminating all the manual tasks having to do with deploying a new release.

According to Marko Anastasov, “a CI/CD service takes over from there by running all tests and deploying the code to production while keeping the team informed about the outcome of every important event.” Your CI/CD program gives you the ability to monitor everything as well as recover quickly if needed. It can also give you the additional benefit of testing through multiple pipelines simultaneously.

Easier Communication and Integration

The CI/CD pipeline allows for everyone’s code to be put into the same project in real time. Doing this will allow the code to synergize; it keeps everyone up-to-date on how the code looks and operates. This avoids the issue of members mixing code and causing bugs down the line.

When bugs occur (as they do in all coding projects), as long as the CI/CD pipeline is active, and a test automation tool is implemented, the errors will be easily noticed, fixed, and eliminated at a much faster rate than normal.

Increased Efficiency

One of the biggest benefits of utilizing the CI/CD pipeline is that with continuous integration, you can edit or add a few lines of code at a single time. Since the changes will be smaller, fewer mistakes will go unnoticed. And because you’d be using a CI/CD tool, the code would also be tested immediately for errors.

This allows you to focus more on the code rather than solely on errors, making the efficiency of the overall project higher. Not only should this save you some time for attending to the actual code, but it also allows you to be more productive and, therefore, waste less money on overtime.

Regardless, the quality of your project would still improve greatly. This is because you have more time on your hands to make improvements and additions while overall having fewer bugs.

Reducing Costs With a Testing Automation

One of the most important aspects of the CI/CD pipeline is test automation. Making tests automatic ensures that any code that gets added or deployed does not include errors. It also ensures that you save money and time considering that you wouldn’t have to do it manually.

This also allows for greater consistency. Since testing is always occurring, you can be sure that all code being inputted is consistent with the previous code. Having that in combination with more testing when the code gets pushed to a new release allows for even fewer errors to make it through, which will again save you both time and money.

Faster MTTR

MTTR stands for “Mean Time To Resolution.” In other words, it is a measure of how quickly you fix errors. The faster you are to fix errors the faster or shorter MTTR is. And the shorter MTTR is, the better off you are. Continuous integration reduces MTTR because there are smaller code changes. Continuous deployment allows those fixes to immediately and automatically go into the production branch.

A fast MTTR is a sign that you understand how to fix your issues, and will fix them when they arise as fast as possible, which also means you are reliable. A CI/CD program may also include a monitor tool that will give you statistics on the types of problems you have and may even predict what kinds of errors will occur in the future. This is amazing for problem-solving.

Faster Releases

Thanks to continuous code integration, smaller and more frequent code changes are possible. Because of that, errors will be easier to detect and then fix. Depending on the CD configuration, whether delivery or deployment, those changes can automatically be pushed into production. This would occur only after automated tests occur. This means that the project version gets updated more frequently when the tests don’t find errors.

CI/CD Leads to Higher Productivity

CI/CD programAll of these benefits add up to the most important benefit of all, and that is increased productivity in your present and future programming career. If your productivity is increased, more of your ideas or goals can come into fruition with less frustration getting in the way.

There are many benefits to the CI/CD pipeline, it’s just a matter of being able to harness it correctly. If you do, then you will become more efficient and reach success easier than you would have before. Not every part of coding needs to be complicated, tedious, or convoluted.

A CI/CD program allows you to focus on producing innovative code. It gives you the ability to constantly test and integrate changes. It also shortens the timeline for deployment and delivery.

Make your life easier by automating your code with a CI/CD program today.

The post 5 Reasons Coders Should Incorporate a CI/CD Program appeared first on Simple Programmer.

]]>
How Can We Automate Testing in a DevOps Setup https://simpleprogrammer.com/devops-test-automation/ Fri, 26 Apr 2019 14:00:10 +0000 https://simpleprogrammer.com/?p=31829 Expertise and strategy play an imperative role in the adoption of a development and operations (DevOps) strategy when developing software. This is because in order to achieve test automation objectives, a group of dedicated testers is required. Automating testing is a difficult technical activity, and it has the ability to ruin the overall DevOps strategy...

The post How Can We Automate Testing in a DevOps Setup appeared first on Simple Programmer.

]]>

Expertise and strategy play an imperative role in the adoption of a development and operations (DevOps) strategy when developing software. This is because in order to achieve test automation objectives, a group of dedicated testers is required.

Automating testing is a difficult technical activity, and it has the ability to ruin the overall DevOps strategy for your project if it is not implemented effectively.

Just understanding the app’s foundation is not sufficient. The team needs to use Agile methodologies for planning and development. Collaboration plays an imperative role if you want your test automation strategy to function in the context of a DevOps setup.

With that in mind, here are four useful tips through which we can automate testing in a DevOps setup.

1. Have Complete Know-How of the User Environment of Your App

Knowing the different parts of an app is not the solution to understanding the exact requirements of test automation. In order to attain complete knowledge of the test automation requirements, it is important to understand all the factors within the user environment for the app.

For instance, if the application is for financial purposes, then security is paramount and the automation testing will focus on security testing. The development team must work collaboratively and assist the testing team to consider all the important aspects when testing the application.

As a result of the continuous support in the form of timely deliverables from the development team, testing teams will be able to create a better automation strategy and flawlessly team up with the development function.

In the example of a financial app, the automation tests will focus only on the security testing efforts while the development team will arrange for effective testing by keeping the testing team in the loop for any developments in the code.

2. Syndicating Technical and Management Experience

In a DevOps setup, the test automation and the development engineers work together to create test scripts and enlarge the scope of their test coverage. These codes and scripts are created to support continuous development and integration activities.

However, the systematic combination of technical and management experience is also important in developing the app. Technical skills allow the developers to make sure there are no glitches and the user experience is excellent.

This setup also has an effect on the management experience. Imagine an environment where everything flows smoothly and where everybody knows what they are supposed to do, who they are supposed to report and deliver to, and what teams they are supposed to interact with. Such a setup is a surefire way to success for any company.

3. Create a Team of Testers to Handle the Test Automation Only

It is very important to understand that different types of testing require different types of expertise. For a manual tester, automation testing is quite the challenge. Therefore, it is ineffective to assign test automation tasks to groups of testers who perform other types of testing.

Automation requires expertise and a strong understanding of planning and implementation. Therefore, it is advisable to create a distinct team that holds expertise and experience in test automation in the DevOps environment.

Automation is not limited to executing tests; it encompasses ranking and planning the tests. A dedicated and experienced team can create value for the entire automation procedure and guarantee tangible outcomes.

4. Encourage the Cultural Shift

DevOps doesn’t restrict itself to technical application and the implementation of development and testing activities. It is a cultural transformation where a DevOps-conducive environment is important to guarantee that the plan is closely monitored and collaborative.

In any organization, a healthy DevOps culture can help the company grow in many organizational values. Not only that, the company can enjoy greater return on investment (ROI), higher client retention, and greater market size.

Operations and developers are required to work together to decrease inadequacies and speed up development activities. A DevOps-favorable environment has to be created to attain the projected test automation objectives.

The aim is to write code that assists in the creation of robust apps within smaller development cycles. Speed and quality can be guaranteed only when the DevOps culture is accepted during the system development instead of being solely task-specific.

Embrace the Transition to DevOps

Like most changes, integrating automation testing into a DevOps setup is something many enterprises will have to get used to.

To do so, you must have a complete understanding of the user-environment of your app and be able to amalgamate technical and managerial experience. It’s also best to establish a separate team solely for automation testing and encourage the cultural shift that will inevitably come with establishing a DevOps setup that also enlists a test automation strategy. Moreover, it is essential to have DevOps now that everything is speeding up with the era of IoT and the increasing demand of digital transformation.

Who wants to stick to legacy technologies or resources? It is high time for advancement for greater ROI, customer retention, and market value.

The post How Can We Automate Testing in a DevOps Setup appeared first on Simple Programmer.

]]>
The Truth About AI and Test Automation https://simpleprogrammer.com/ai-test-automation/ Wed, 19 Sep 2018 14:00:48 +0000 https://simpleprogrammer.com/?p=30011 Software testing has gradually evolved in the past few decades. In the past, teams were accustomed to the waterfall methodology: Everything was sequential, from requirements to product deployment. Only after the development phase was completed did the testers got their hands on the product. Historically, testers would find a number of bugs in this phase,...

The post The Truth About AI and Test Automation appeared first on Simple Programmer.

]]>
Software testing has gradually evolved in the past few decades. In the past, teams were accustomed to the waterfall methodology: Everything was sequential, from requirements to product deployment.

Only after the development phase was completed did the testers got their hands on the product. Historically, testers would find a number of bugs in this phase, and it would take a lot of redesign and rework to fix them. This resulted in a lot of wastage, from time to effort and cost, plus team morale.

But in the current state of testing, most companies are following Agile processes, such as XP, Scrum, Kanban, or some variation of these. The main goal is to find bugs fast, fix them quickly, and release software faster.

In order to achieve this goal, there is a huge need to complement the already existing manual testing process with automated testing. This is a vital component of Continuous Integration (CI), Continuous Delivery (CD), and DevOps, which most teams are now following to make their Software Development Life Cycle (SDLC) process more lean and effective.

Various tools and frameworks have evolved in the past decade to help with automated testing, but one approach worth talking about is the use of Artificial Intelligence (AI) in test automation.

AI test automation

De-Mystifying Artificial Intelligence

Let’s first take a step back and de-mystify AI. At its most basic level, AI is a technology that can comprehend, sense, and learn, and use computers to solve problems typically requiring human intelligence and understanding.

Another way of looking at it is, AI applies human skills and tendencies to inanimate objects or ideas. Much like automation, AI makes it possible for technology to complete real human tasks.

Contrary to popular opinion, AI is neither a distant reality nor a concept based on the plots of science fiction; instead, it has infiltrated the technology scene and is fueling the innovations that touch our daily lives. From chat bots posing as customer service representatives to search results and traffic predictions, on any given day, AI is all around us.

Here are some mind blowing statistics about AI adoption:

  • According to a recent study by Narrative Science, 61% of businesses implemented AI in some way in 2017. The adoption rate is only growing in 2018.
  • Another study from Juniper Research has found that global retailer spending on AI will reach $7.3 billion per annum by 2022, up from an estimated $2 billion in 2018.
  • A CMO article claims that by 2035, AI will help to improve labor productivity by 40% and enable people to make efficient use of their time.

Influence of AI in Test Automation

AI has already started influencing test automation in various ways, resulting in a considerable amount of time saved in authoring and executing tests, creating more stable tests, finding bugs fast, and releasing software much faster to meet customer demands. Here are some of the ways this is happening.

Faster and More Stable UI Tests

As part of the continuous testing process, software development teams have unit tests, service/API level tests, and user interface (UI) tests. The common problem with UI tests specifically is that they are slow and brittle and involve high maintenance. AI can avoid this with the use of Dynamic Locators.

This is a strategy by which the AI parses multiple attributes of each and every element the user interacts with in the application and creates a list of location strategies, in real time. So, even if an attribute of an element changes, the tests do not fail; instead the AI detects this problem and goes to the next best location strategy to successfully identify the element in the page.

In this way, the tests are more stable, and as a result, the authoring and execution of tests is really fast as well.

AI test automation

Reducing Maintenance and Eliminating Flaky Tests

One of the most common problems with test automation is maintenance.

For example, say we have 100 automated tests running on a daily basis to ensure the main functionalities of the application are still stable; What if the next day we come back to work and find that half of the tests have failed? We would need to spend considerable amounts of time to troubleshoot the failures and investigate what actually happened. This involves figuring out ways to fix the failures and implement the fixes. Then, we re-run the automated tests to ensure everything passes. Does this ring a bell?

AI can avoid issues like this due to its self-healing mechanism. It can start detecting problems in the tests before they even occur, thus proactively fixing tests instead of us reacting to them.

Based on the number of times the tests have run, the AI can figure out which tests are stable or flaky. As a result, it can give us data on what tests need to be modified to ensure test runs are stable.

Finally, based on large numbers of test runs, AI can optimize the wait times used in tests to wait for the pages to load and also can handle tests running on different resolutions. All of this adds up to a considerable decrease in the time spent on maintenance of tests and helps to solve one of the biggest bottlenecks of continuous testing.

AI test automation

Continuous Learning from Production Data

In this fast-paced environment where customer is king, it is important to observe and learn how customers use our product. This is true whether you have a web, mobile, or desktop application.

With autonomous testing, we now have a way for AI to start observing and learning how our customers are using the product. Based on this, it can start creating tests based on real user data.

It is smart enough to identify commonly used actions such as logging in/out of the application and cluster them into reusable components. Then it injects these newly created reusable components into our tests as well. Now, all of a sudden we already have actual tests written by the AI based on real data, along with reusable components that can be used within other tests as well.

AI test automation

This reminds me of a quote from the great Steve Jobs: “Start with the customer experience and work backwards.”

Removing Dependencies

Another challenge of test automation is writing tests for a system that may have dependencies on other modules that may or may not have been implemented yet. Usually during these times, we mock responses from a server or database. Now AI can help to do this for us.

Once we have authored some tests and have run them consistently for a period of time, the AI can start recording all the server responses. The next time we run the tests, instead of talking to a server or database, the test will access the stored responses (which was facilitated with the help of AI) and will continue to run without any obstacles.

As a result, the tests run much faster, since the delay in waiting for a response is eliminated and the need to rely on a physical database or server has completely been erased.

AI test automation

Ease of Authoring and Executing Tests

Some of the biggest obstacles keeping companies from moving forward with automation is the amount of time and effort it takes to author and execute tests with the chosen tool or framework and the availability of skilled resources to do this task.

Even when companies decide to move forward with automated testing, teams have to spend considerable amounts of time authoring and executing tests due to complexity of the application, tools available, and the programming language used.

Now, there are AI-based tools that help to mitigate these problems. Tests that used to take one week to author and execute can now be done in a matter of hours using AI. This is possible with the use of Dynamic Locators and the ability to easily create reusable components, do data-driven testing, author and execute tests quickly, and integrate CI/CD systems easily with public and private grids. As a result, we are able to have reliable tests, more test coverage, less maintenance, and faster release cycles.

Also, this has opened up a new era in test automation where nontechnical people can get involved in test automation as well. This helps to increase collaboration within teams and encourages everyone to own the test automation effort. AI is now bringing a whole-team approach to test automation.

AI test automation

Releasing at the Speed of Development

With AI powering the transition to autonomous testing, reducing the maintenance to a minimum, and creating more reliable tests, the ability for teams to release faster is better than ever.

With AI and autonomous testing, quality assurance (QA) can focus on exploratory tests, while a big portion of the tests are continuously created and updated automatically. Now, your release frequency is only limited by how quickly your developers can code. It is also easier for QA to maximize user coverage by connecting authoring of tests with production apps mapping to real user flows.

Now, we have the ability to take a risk-based approach and base our decisions on real data. Most of all, we are ahead of the game by proactively fixing issues instead of reacting to them, because of the self-healing mechanism of the AI.

Also, we are now able to create more user scenarios in short period of time. This means you can find bugs fast and release faster. The future of testing has only become brighter with AI.

If you have experienced or heard of other ways to implement AI in test automation, please share your thoughts below in the comments section.

The post The Truth About AI and Test Automation appeared first on Simple Programmer.

]]>
7 Bad Habits to Avoid as a QA Engineer https://simpleprogrammer.com/qa-engineer-habits/ Fri, 10 Aug 2018 14:00:35 +0000 https://simpleprogrammer.com/?p=29742 Most people would agree that software quality is important. We have seen the results of buggy software in all kinds of situations: from Mars probes malfunctioning and chemotherapy machines administering lethal doses of radiation, to telecommunications systems experiencing a cascade failure. It would seem logical to assume that software testers would be much-valued members of...

The post 7 Bad Habits to Avoid as a QA Engineer appeared first on Simple Programmer.

]]>
Most people would agree that software quality is important. We have seen the results of buggy software in all kinds of situations: from Mars probes malfunctioning and chemotherapy machines administering lethal doses of radiation, to telecommunications systems experiencing a cascade failure. It would seem logical to assume that software testers would be much-valued members of a development team. Yet sadly, that is not always the case.

Some software developers, product owners, and managers assume that quality assurance (QA) engineers are people who wanted to be developers and lacked the necessary skill or grit to succeed. Unfortunately, there are a few testers who fit this description, but most testers are people who genuinely care about the quality of the product they are testing.

Why then have testers gotten such a bad reputation? Usually, it’s because of bad habits they have developed over the course of their careers.

This article will outline seven habits that QA engineers should actively avoid and the good habits to replace them with, in order to ensure that QA engineers are doing high-quality work and earning the respect of their peers.

Bad Habit #1: Testing Things You Don’t Understand

We’ve all been there: There’s some obscure story on the JIRA board that involves some legacy back-end code, and no one is entirely sure what the code does or how to change it. The developer tasked with the story has done enough research to fix the code but hasn’t put any detail in the story about how it works or what change has been made. The developer says to you, “Just run this request on this server, and if you get this response, then it’s fixed.”

Here’s the problem with this scenario: How do you know the developer is right? If the issue is not fixed, and there is a failure in production, your manager will come back to you with questions. Do you really want to have your only response be “The Dev told me to do this, and it worked, so I moved the story to Done”?

The Good Habit: Ask questions. Ask your developer to explain to you how the feature works and what changes were made to it.

Keep on asking clarifying questions until you really understand what is happening. In doing this, you may bring up points the developer hadn’t thought of, sending them back to improve their work.

Software developers are continuously learning, and you should be as well. Listen to podcasts and read blog posts to keep up with  the latest technology trends and testing strategies.

Bad Habit #2: Testing Only What the Story Tells You to Test

Our development stories often contain acceptance criteria (AC), which outline exactly how the new feature or fix should behave. These are often written by the product owner, and sometimes by the developer. The AC are helpful and are certainly better than having no AC at all, but they often contain only “Happy Path” scenarios.

Even when the developer writes the AC, they may not include test scenarios where bugs could be hiding, not because they are trying to be duplicitous, but because the scenarios might not have occurred to them. Testers will often assume that the developer knows best and will test only the AC. This means that there may be critical areas that are left untested and bugs left undetected.

The Good Habit: Think outside the box. One of our skills as QA engineers is being able to think about what might go wrong; we need to use this skill with every story we test.

Before you sign off on the AC, ask yourself, “Can I think of anything else to test here? Is there anything I’ve missed?” This will often help you find bugs in areas that no one else thought of.

Bad Habit #3: Assuming That Odd Behavior Is Correct Behavior

Often, when we are testing a new feature, we run across behavior that doesn’t make sense. Perhaps it’s an odd page refresh or a navigation to a place we weren’t expecting. Or perhaps a button appears where we weren’t expecting one.

It’s easy when we are testing on a deadline to focus so much on the AC of the story that odd behavior gets pushed to the back of our mind. We might tell ourselves, “I’ll ask the Dev about that when this story is done,” (and then we forget), or we say, “Well, I’m sure she knows what she’s doing; it’s probably supposed to do that.”

The Good Habit: Listen to your instincts. If the behavior is odd, there’s a very high probability that end users are going to find it odd as well; they may even find it so frustrating that they stop using the application.

We need to remember that our end users are our customers. We are the last line of defense in making sure that they have a good experience with our application. If your instinct is telling you that something isn’t quite right, document your testing and speak up about what you are seeing.

Bad Habit #4: Chasing Things Down the Rabbit Hole

This is the opposite of Bad Habit #3; sometimes QA engineers are so focused on finding every single thing wrong with an application, no matter how tiny, that they wind up in “analysis paralysis” and bring their team’s progress to a halt.

I remember asking a fellow QA engineer what her favorite bug was that she had found in the course of her career. She excitedly told me about a bug that involved clicking a button several times, navigating forward and backward through a pair of pages, and then scrolling quickly, all in one specific browser.

While I’m sure this bug was fun to chase down, it involved behaviors that a user would never, ever do, and the bug itself wasn’t particularly harmful. I wondered how many other real issues she could have found while she was trying to reproduce this one obscure issue.

The Good Habit: Focus on real-world use cases. Always remember that our focus should be on making sure that our software works well for our users and that our software is well-protected from malicious users. We are not merely finding bugs for the joy of the hunt.

If you find yourself going down the rabbit hole, ask yourself if your time could be better spent testing more realistic use cases.

Bad Habit #5: Automating Tests for the Sake of Doing Automation

QA engineers who have learned how to write automation discover that automating things is fun. There is a certain rush that comes with solving a technical challenge and watching your test run automatically.

But automation is not always the answer. When we have a new feature to test, it’s important to take time and get to know the feature as an end user would by actually using the feature. When we jump into automation before we’ve done this, we can wind up automating tests that don’t exercise the feature well.

We can also miss key features. For example, if we had a new search feature that searches by a date range, an automation engineer might spend all their time figuring out how to pick dates using Selenium test software and never notice that it was possible to enter in a start date that was after the end date.

The Good Habit: Take the time to do manual, exploratory testing to get to know a feature. Ask questions about how the feature will be used. Think about what your end users will do. Find as many bugs as you can. Then, start to think about how you should automate it.

Bad Habit #6: Creating Complicated and Flaky Tests

When I first learned how to automate user interface (UI) tests with Selenium, I automated them like they were manual tests. My tests had lots of steps and implicit waits. The more steps a test has, the more likely it is that some test step will fail, causing the entire test to fail. Implicit waits are unreliable because waiting for a set number of seconds does not guarantee that the element will become present and clickable in that time.

Consequently, my tests were extremely flaky.

Every morning when I arrived at work, I checked to see which tests had failed and reran all of the failures. Then I would tinker with the tests that had failed a second time to see if I could get them to work correctly. This was a tremendous waste of my time.

The Good Habit: Remember that the point of automation is to make your work easier, freeing you up to do more exploratory testing.

Automated tests should be simple, with each test checking only one thing. Take a look at your UI tests and see if they could be automated with API tests instead. Application programming interface (API) tests are faster and more reliable than UI tests because they don’t rely on responses from the browser. When a UI test is needed, be sure to use explicit waits rather than implicit waits to reduce flakiness.

Bad Habit #7: Accepting a Poor User Experience

Sometimes, when we are working on a deadline and have many stories to test, we look only at the functionality of a feature. If the feature works and has no bugs, we call it done and move on.

But it’s important to remember the end users. If a user doesn’t understand what to do on the page or finds that they have to click several times in order to get something done, they will be frustrated and won’t want to use the product.

I saw an example of this recently when I was asked to fill out a survey. The questions I was asked required long answers, but the survey fields were so small that I could only see one line at a time, making it difficult to type and proofread my entry. I’m sure that the QA engineers that tested the product verified that the field could be typed in and that the entry was saved, but they didn’t consider how difficult it would be to use.

The Good Habit: Always think of your end users when testing your application. Find out from your product owner what the expected workflows are and run through those workflows. Ask yourself what you would think of the product’s behavior if you were the end user rather than the tester. If the behavior would frustrate you, advocate for a change in the behavior.

Remember Why You Are Testing

In our daily work as testers, it’s easy to get distracted by deadlines and technical challenges. We are great at focusing on the minutiae of software, which is why we are good at finding bugs. But we must never lose sight of why our company exists: to create software that people will use.

The end result of all of our tasks must be the assurance that a user will be able to use our product intuitively, safely, and easily. When we consistently focus on the quality of the products our team is delivering, we earn the reputation of being effective QA engineers as well as the respect and trust of our developers, product owners, and leaders.

The post 7 Bad Habits to Avoid as a QA Engineer appeared first on Simple Programmer.

]]>
The Different Roles Within the Field of QA and Testing https://simpleprogrammer.com/different-roles-of-qa-and-testing/ Wed, 25 Jul 2018 14:00:05 +0000 https://simpleprogrammer.com/?p=29596 This piece was a collaboration written by Kayleigh Oliver and Daniel Sayer, writer of the Unexpected QA blog. There are so many job titles which cover the generic role of someone who works as a tester or someone within quality assurance (QA). Is it all recruiter babble? Does it denote the same roles and responsibilities?...

The post The Different Roles Within the Field of QA and Testing appeared first on Simple Programmer.

]]>
This piece was a collaboration written by Kayleigh Oliver and Daniel Sayer, writer of the Unexpected QA blog.


There are so many job titles which cover the generic role of someone who works as a tester or someone within quality assurance (QA). Is it all recruiter babble? Does it denote the same roles and responsibilities?

Or are there significant differences in what a person will be expected to undertake determined by these job titles?

Here, Kayleigh and Dan will discuss the various current job titles for non-specialists they have encountered in their respective careers and work to define the high-level responsibilities of each title.

More specifically, they will describe the role of a tester or someone working in QA and put forward their explanations of what each title means, so you can formulate your own definitions and decide which would be best for you to pursue.

QA Engineer

Dan: The first thing to do when analyzing the job title is to break it down into its constituent parts, with QA short for quality assurance. I believe these parts convey the idea that the person occupying the QA role needs to focus on more than just testing. They should be the advocates of quality in their team, promoting others to increase the levels of quality in the work they undertake, the processes they follow, and the code they write.

The “engineer” portion in the context of quality assurance denotes more involvement in the release process for both defining and ensuring features, and changes are released with minimal negative impact to the end user.

Essentially, if we were to draw a Venn diagram of all quality/testing job titles, I would see “QA engineer” being slap bang in the middle, accounting for a little bit of every segment: testing, coding, process improvement, and championing.

Kayleigh: I agree with Dan about the QA part of this job title; any role with “QA” denotes that the person will be an advocate of the quality of the product.

The end user isn’t usually involved within development, so it’s the QA’s role to champion their objectives for that end user and to help improve the processes used during development to ensure a high-quality product is delivered.

But when I see the word “engineer” in a job title, I don’t think about the release process. This signifies that the role requires someone with technical skills. After all, the word “engineer” is rooted in the ability for that person to be able to construct, build, and develop something.

QA Developer

Dan: This is an interesting one. I would argue—and I’m probably going to cause some controversy here—that this role is made up. Linguistically, it doesn’t make sense to both test and develop (with testing being a large proportion of the QA responsibility to the team).

One of the reasons companies employ QAs as a separate entity from developers is to ensure functionality checking is done by a fresh pair of eyes. This is the same reason why QAs should employ techniques used by developers when writing code, such as code reviews. Some companies do not have QA as a separate unit and expect developers to test their own work; however, they aren’t called “QA developers.”

Therefore, if we take the perspective that the primary goal of any QA is to ensure the quality of the end product, it doesn’t feel feasible for someone to be a QA developer.

However, if you flip this on its head and try to envisage what someone would do if hired into a role with this title, I would imagine they would spend more time working on tools that enhance QA and be less involved in the production of features and changes to the main product. Why then not just have the title of developer?

Kayleigh: I disagree here. Not all developers are involved in the development of production code. Some just maintain the code and write tests, but they are developers and their focus is what’s important. They are expected to write code that contributes to the development of features and continual improvement of those features within a readable, extendable, and maintainable codebase. A QA developer would focus on writing code that contributes to the development of tests for features within a readable, extendable, and maintainable codebase.

To me, this role would have someone with technical skills that (as Dan so rightly suggested) could be working with other teams like DevOps or solo, building testing tools to aid QA and testers during their day-to-day work.

This role could also be another way to refer to automation engineers. These are typically testers that spend the majority (if not all) of their time creating automation scripts that run on builds to detect defects before the project reaches production. Developers develop, but QA developers would have a particular focus on quality and how they can improve the quality of the product.

QA Tester

Dan: When I see the word “tester,” I immediately think about the manual process of pushing buttons and clicking through websites. This title denotes that the occupant focuses more on testing as a manual task but is still involved in shaping the overall quality of the processes in getting changes or features released (denoted by the QA section of the title).

The role of QA tester isn’t one I have seen that regularly, with my focus being in public services, online gambling, and web and app services. Usually, employers either want the tester to have a direct influence on the product from the start of the process or only test it once it’s completed.

Kayleigh: I agree that the role of a QA tester is to perform manual testing. Again, this role requires the tester to be an advocate of quality from the end user’s perspective and to champion change to improve the processes that build the product.

Historically, you’d find that testers working within the games industry would perform only manual testing, so they were called “QA testers.” However, more industries are recognizing the importance of releasing a high-quality product and how a low-quality product can affect their reputation, brand, and finances. Even the games industry has started employing QA engineers and automation engineers. This distinction in titles makes me more confident that this role is purely manual.

QA Analyst

Kayleigh: I think this is quite similar to the QA tester. However, I think the QA analyst would be more involved in the development cycle during the user acceptance testing (UAT) stages.

Dan: I agree that there are definite similarities to the role of QA tester; both roles have their main focus on manual testing. I was once told that the difference between a QA analyst and QA engineer was that the engineer was in charge of the release process whereas the analyst’s focus was up until the point of release. I’m sure there’s more to it than this anecdote, if we put this job title under the microscope. It has similarities to a business analyst and, potentially, crosses over in roles and responsibilities such as UAT stages, as Kayleigh mentioned.

Automation Engineer

Kayleigh: This is probably one of the most well-known job titles on this list so far. The role of automation engineer is to develop (hence the engineer part of the job title) automation scripts to test production code.

The types of tests written will largely depend on the company you work for. Automation engineers tend to write integration tests and UI tests.

Usually, automation engineers are more likely to write UI tests since they test the application from the end user’s perspective. But depending on the company and its size, this role could write anything from low-level unit tests to high-level UI tests.

Dan: Again, I very much agree with you. “Automation engineer” is pretty much the Ronsil™ of job titles (does what it says on the tin). These guys (or girls) write automation tests, and that’s pretty much all they do. However, I don’t wish to belittle the task. With such a wide range of ways to contribute to automating the testing process, from unit to UI, there’s enough work to do to deserve a person specializing in this position.

Having been in a position where I was expected to write automation tests, these scripts need to be kept on top of. The slightest change or new feature can render all your tests obsolete, which is why strategies such as Page Object Model were devised; however, someone does have to implement this.

Software Tester

Dan: My thoughts on the role of a software tester are that it’s similar to that of a QA tester: mainly manual testing, focusing on the product and not on the process. It feels very much like a position where the work involves testing the product, and it either meets the expected criteria or it doesn’t.

My understanding may be swayed by the types of candidates I interviewed who came from a software tester background, but it did feel as if there was a perceptual difference between software tester and QA engineer.

Kayleigh: I would mostly agree again with Dan here. The software tester would focus on testing the functionality of the product to ensure it meets its intended use, but not test it from the perspective of whether it fulfills its business need. The word “software” is a generic catch-all that dictates you are a tester of digital products and not mechanical, like a lab or electrical tester.

Test Engineer

Dan: I believe the lack of specifying “software” in the job title identifies that the product under test could be hardware. However, I feel that this is where the differences cease. There doesn’t seem to be a hardware tester job title that’s employed with much frequency, so this is used for manual testers for hardware.

Kayleigh: Again, I’m disagreeing. Whenever a job title includes the word “engineer,” it implies a level of technical ability for that role. But other than that, I would agree this role focuses more on testing the product’s functionality rather than the business value it adds or the end user’s perspective.

Test Analyst

Dan: Test analyst is more of a Waterfall development process job title. Test analysts can either identify the targets from testing activities and enact the tasks to achieve these targets, or they can work in a more advisory position, assisting with preparation of test cycles, helping users during acceptance tests, and producing reports and analysis of the outcomes.

Kayleigh: This would be one role that suggests you’re going to solely be doing manual work. However, this role would focus more on testing from an end user’s perspective rather than merely ensuring the features are functionally performing.

Software Development Engineer in Test (SDET)

Kayleigh: This title was first used in 2005 by Microsoft. This title is the most technical for someone in the testing field because their role is to both develop and test, often across different stages of development. The person undertaking this role may develop many different types of tests, for example integration, contract acceptance, and UI.

To be able to perform all of these types of tests, you need to have an understanding of what makes a good test, the types of testing required at each level, and how to implement them.

Giving this type of technical tester a title with the word “development” means the candidate should have a greater technical ability. It also makes the title easier to understand to those outside of any development role. Anyone can guess what a software developer does, but you need to also explain the role of an automation engineer. This is the role that I believe is the closest to an SDET.

Dan: As you said, Kayleigh, this role has been around for a while now. An SDET is a developer that focuses on testing. SDETs are highly proficient in coding and development practices but do not get involved in the development side and remain focused on ensuring the product is in a testable position.

I feel the perception is that SDETs would rather code a script than manually execute a test, regardless of the time and effort it would take. I am aware of several places that would utilize SDETs to refactor code to make it more testable. This isn’t the norm but does go to show the wide skill set those employed in this position need to have. But how is this role different from that of automation engineer? I believe it’s the same job under a different name and cannot see a noticeable dissimilarity between responsibilities. However, if I was in this position, I would rather be known as a software development engineer in test. It has a nice ring to it, don’t you think?

Do Job Titles Really Matter?

Ultimately, a job title can give you only so much information into what you will be doing. Many jobs will be posted by non-QAs (recruiters, development managers, etc.) that even if there was a consensus on the titles above, there would still be so many nuances that you have to look at the job description to make an informed decision. You’ll find some uniquely named positions after a quick search on popular job sites, such as Test Ninja, which shows that our list and discussion isn’t exhaustive.

We both agree that the description of the role is more important than the title, as it’ll convey the detail and day-to-day actions of the role. However, job titles are still used to denote the level of authority of an individual at a glance, so it does matter what title you are working under.

What to do if Your Job Title Isn’t for You

Again, it’s true that a job posting may be different from what you actually undertake in the role. You may find that your role is different than the title you originally applied for.

If you’re not happy with your current title, we would suggest you speak to your manager and negotiate a title change in your next performance review. Remember to go with evidence of the additional tasks you undertake so you can justify a title that more represents your day-to-day workload.

If you’re not happy with the extra responsibilities you’ve undertaken which don’t usually fall under this role, we suggest you also talk to your manager. Maybe these extra tasks are pulling you away from doing your best work and spreading yourself too thin. Whatever you may be unhappy with, come to a compromise with your manager; don’t just carry on.

The post The Different Roles Within the Field of QA and Testing appeared first on Simple Programmer.

]]>
A Beginner’s Guide to Testing Blockchain Applications https://simpleprogrammer.com/testing-blockchain-applications/ Fri, 23 Mar 2018 14:00:07 +0000 https://simpleprogrammer.com/?p=28381 During the last few months of 2017, bitcoin and other cryptocurrencies were being talked about by some media sources on a daily basis. These currencies, which had been around for years, were suddenly experiencing major growth. For example, the price of bitcoin has grown from just under $750 in January 2017 to $5,856.10 in mid-October...

The post A Beginner’s Guide to Testing Blockchain Applications appeared first on Simple Programmer.

]]>
During the last few months of 2017, bitcoin and other cryptocurrencies were being talked about by some media sources on a daily basis. These currencies, which had been around for years, were suddenly experiencing major growth. For example, the price of bitcoin has grown from just under $750 in January 2017 to $5,856.10 in mid-October 2017.

This massive growth made it a major talking point. So, as these newer currencies came more into the public domain, the technology behind cryptocurrencies was also beginning to gain attention. This technology is the blockchain.

Blockchain applications are being adopted by some of the biggest industries around the world and blockchain coding as a career is becoming more popular. Because of the nature of blockchain applications, it further supports how important testing and testers are, and that the field will be more highly thought of and sought after in the future. So as testers, it’s only right to wonder how this new technology will affect your day-to-day work, new opportunities, and current skill set.

What new tools will you have to learn to test blockchain applications, and what skills are needed to test them?

Here, I will outline what the blockchain technology is and how we, as testers, can prepare ourselves for testing blockchain applications.

What Is Blockchain?

Blockchain is a data structure that exists in many locations at once. You can only add to the blockchain. No deletions or updates are permitted. The data held within a blockchain is decentralized, which means a copy of the existing blockchain is on every machine in the network.

Additions to the blockchain can be seen on every computer in that network and the transactions are cryptographically linked to the previous transaction. Therefore, carrying out fraudulent transactions is very difficult to perform. To do this, someone would have to rewrite their history to the beginning of time, which is extremely resource-heavy.

In order to update every machine in the blockchain, the machines have to sync to have a common history. Although all machines will eventually have the same data because of this syncing action, only the more recent transactions are synced more often.

For a new transaction to be added, the decision is reliant on the majority of participants in the blockchain. Once the transaction’s authentication has been validated, the new block is added to the blockchain.

What Is It Used For?

Currently, blockchain is used mainly by the financial and automotive industries because of its highly secure structure. As I mentioned earlier, it’s also the technology that underpins cryptocurrencies like bitcoin and Ethereum.

Not all blockchain technology is open-source. There can be private blockchains like the ones used in banking systems.

What Types of Tests and Techniques Can You Perform on Applications Built on Blockchain?

There are many different types of tests that can be performed at the various stages of developing software projects. Below are a few types of tests that can be utilized to ensure a high level of test coverage and quality for blockchain applications.

Unit Tests

Unit tests help developers ensure their code is performing correctly at the lowest levels and smallest parts of functionality. This should always be the first line of defense to ensure an application catches the majority of bugs early during development.

Integration Tests

Integration tests help developers and test engineers ensure the communication of their code between different components, and possibly between internal and external systems like databases.

User Interface

User interface (UI) testing uncovers how the application works from the end user’s perspective. It’s important to ensure that you carry out UI testing to make sure their experience is positive or that they at least get the correct feedback from the application when it doesn’t perform well.

Application Programming Interface

Application programming interface (API) testing gives you confidence that you’ve validated the responses that your application receives from external APIs and makes sure the formats of your API requests are correct and being handled correctly.

With blockchain applications, there is also a similar type of technology to APIs that allows you to adopt the same testing practices for APIs. These are called smart contracts.

What Are Smart Contracts?

Smart contracts are a big part of the validation technology within a blockchain. A smart contract is a “set of rules in the form of programmable constructs that are capable of automatically enforcing themselves when predefined conditions are met.” For example, a precondition could be transactions trying to append to a specific ledger will undergo additional validations or go through a different set of validations that are more robust.

Although a smart contract is very similar to an API, whereby it has public functions that can be called by anyone registered on that blockchain network, it cannot call external web APIs.

So why do I think that testers are extremely important when testing blockchain applications over other types of systems? Simply because once a contract is deployed to a blockchain, it can never be changed. So you have to be very confident the testing that’s performed is of a high level of quality and that everything that should be covered has been covered.

If a defect is found in production, then a new version of the contract has to be created and deployed. New versions of existing contacts can’t simply get the existing data transferred in; you have to manually initialize the previous data with the new contract.

Updating a contract and rolling back an update is also not a viable option; this increases the complexity of development and means that the importance of implementing and running unit and integration tests on your application before it reaches production could save you major time and money in rectifying defects.

What Skills Do Testers Need for Blockchain Applications?

Although blockchain applications are relatively new in software development, I don’t think testers need to adopt new skills in order to test this type of technology.

Some of the skills I’ve highlighted below are natural skills of good testers or simply skills that you learn early on in your testing career, which grows with your experience in the field.

Critical Thinking

The ability to critically analyze and think about and around a problem is a timeless skill for testers and will be even more sought after for testing blockchain applications.

Testers think about problems such as: Will transactions still execute if x, y, and z are not done? What happens if the network has lots of transactions waiting to confirm? What feedback is given to the user in these cases? Should this be the feedback given to the user? Or is this feedback exposing any security risks?

Another thing to consider if embarking on a new project is to question whether blockchain is the best technology for your use. It’s the new shiny toy, so everyone will want to adopt it, but it may not be suitable for what you want to achieve.

Things to keep in mind are compliance issues; for example, you shouldn’t store health or criminal records, as there are no deletions allowed. So, when criminal records for minors can be wiped, you won’t be able to do so with this technology.

Test Design Techniques

During the ISTQB-BCS Foundation Software Testing syllabus, you are introduced to test design techniques. Knowing even the basics of test design techniques, like boundary value analysis and equivalence partitioning, will make sure you are constantly thinking about and checking the inputs and outputs of the application.

Things to consider could be: How will the application act when you input values that are within, on the edge, and outside of the boundaries of acceptable values? Will the transaction complete? If not, what type of error will be returned? Is this error code correct for the type returned? Should it return anything at all?

Automation

Strong automation skills in all languages, either for lower-level unit, mid-level integration, or API or high-level UI tests, are good skills that can be transferred to testing blockchain applications. Having a solid foundation of automated tests will be needed to ensure that the majority of issues are found early in development.

Manual UI Testing

If a solid foundation of automated tests is put in place, testers can focus on the outlier issues that can more easily be found via exploratory testing performed manually.

Being able to work independently, investigating different areas of the application, trying to find weak areas, and being able to successfully reproduce these are always skills that great testers will need. Despite the world looking to automation to perform a lot of the repetitive and arduous tasks, manual testing skills are still something to hone and improve.

Learn New Tools Quickly

As new technology comes to light, the list of tools to test this technology will also grow. You’ll need to be able to learn how to use these new tools quickly and judge which is the best for what you’re trying to accomplish.

Future-Proof Yourself and Prepare for Blockchain

Hopefully by now, you have a better understanding of the blockchain technology and no longer think it’s as scary as your first thought.

I’m sure if you’re a tester, you already have the foundations of the skills I’ve outlined above. My advice is to push further into an area that you have an interest in and possibly try to improve in the areas where you are weakest to give you the best chance to grow your skills when testing blockchain applications.

The post A Beginner’s Guide to Testing Blockchain Applications appeared first on Simple Programmer.

]]>