🔌 Engineer honesty moment
Today, for a change, I'm not starting with what I did. I'm starting with a question for you, on the other side of the screen.
This is day nine. If you've read everything before it, be honest: it's not just me, is it? This story looked about as trivial as a story gets, and it turned out not to be simple at all.
Every other keynote now, someone walks on stage and shows how to build a flight aggregator in three easy steps. Or a translator. Or whatever's next. In theory it sounds great, and it sells the product.
In practice, when you need one very specific thing, quick results like that don't fit.
I had a quick result. On day four. It had no input field.
You could say: well, you just don't know how. You're using a microscope to hammer nails.
No. I'm not new to this. I have fifteen years of programming behind me, and the strongest models there are. And a task that sounds trivial has still stretched into a very real chunk of time.
And again: I'm not writing this from the point where it's all done. I'm writing it from somewhere around, say, forty percent. Forty, sixty or twenty — we'll only find out at release. And even then: what's a release without a screw-up and an emergency hotfix?
Here's what I think everyone should know about building software today. It got easier. It is still not magic.
Building things is hard. If, that is, you want to build something that's worth anything.
And building junk — go ahead and try. But will you have the motivation to keep going, and keep spending your time on it?
That's not a rhetorical question.
⏳ Thursday
Now, what happened today.
Yesterday I promised myself to go through the app through the eyes of whoever will check it before the store. I actually started last night. And to explain why, I need to explain how my week works.
The AI I work with has a weekly limit. My week ends on Thursday.
Once I burned through the whole weekly limit in three days. The rest of that week was miserable: everything I wanted to do ran into "later".
Since then my week leans towards Thursday. I know there's still some left, and that it resets soon anyway, so Thursday is when I spend hardest.
And an audit is the most expensive thing you can ask for. So that's when it happened: last night.
I asked the AI to go through all of the code as if it were an App Store reviewer, paid to find a reason to say no.
Today it's the train again. Four hours there and back — enough to read the result properly instead of skimming it.
🗺 The map
What came out wasn't a list of comments. It was a map.
Four passes in parallel: code quality, security, store readiness, tests. The heaviest findings were checked a second time, against the source, not from memory.
Four items — "the upload gets rejected on the spot".
Five — "critical".
Fifteen — "important".
Twenty — "minor".
And a separate section, which I liked more than all the others: "verified sound — don't fix".
Encryption. The locks. Search. The clipboard. The audit says it outright: this is built right, leave it alone.
I think that's the most underrated part of any review. Saying where things are fine isn't politeness. It's protection against the next person who comes along to "improve" them.
The map also handed out the work so the limit wouldn't burn for nothing. The risky parts — the vault's lifecycle, privacy, how the board draws itself — went to the strongest model. The mechanical ones to a cheaper one. And whatever can only be done by hand in Xcode went to me.
📦 What was riding along
The first of the four "rejected on the spot" items: the app has no sandbox. The Mac App Store won't take that, full stop. It's boring, it's a ten-minute fix, and it's exactly the kind of thing I didn't know about Apple's platform.
The second one, though.
Remember the day Xcode opened? I copied the project's documents into the app's folder. The strategy, the requirements, the plan, every task file. And I wrote that there were now three copies, byte for byte, and one of them was inside the app itself.
Turns out "inside the app itself" wasn't a figure of speech.
We worked out on day four that in Xcode, the folder decides. And everything in this one gets packed into the app. So everyone who bought jpaste would have got my strategy along with it. The positioning. The price, and why that price. The list of what I plan to build, and in what order.
Twelve files. Over six thousand lines. There's even a section called "Why $9.99, not $4.99".
I wasn't embarrassed. It's all still in development; nothing has gone to the store. The price in that document is the price as it stands. Maybe I'll redo it. We'll see.
But since I asked you about price yesterday, it's only fair to answer myself. Not as the person who makes jpaste — as a buyer.
My budget for subscriptions is zero. One more monthly line on my statement holds no interest for me.
For a good tool I'll pay once — and I have — up to twenty dollars. But somewhere past fourteen, it turns into a real fight.
As of today, those files are no longer inside the app.
Today's commit deleted almost nine thousand lines and added four and a half thousand. Twice as much deleted as added.
Only three hundred of the deleted lines were code. Another two thousand were translations, rewritten. The rest were my own documents, going back where they belong.
🔐 The vault, finally
Two days running I wrote the same thing about the vault: not seriously tested yet, it's a big area, it needs testing and testing.
Today it got its turn.
And the main finding was exactly the kind I'd been afraid of.
If you interrupted the vault setup halfway — closed the window, cancelled, crashed the app — the board stayed marked as a vault while its contents sat there in plain text. A lock on a door that isn't there.
Now the setup is atomic: the board's level only switches after the encryption has actually been written. And an interrupted setup can be finished from the lock screen.
Plus a few more things I hadn't thought about until they were pointed out:
- a hidden snippet copied to the clipboard now disappears from it after a minute
- while a protected board is open, the window stays out of screen recordings
- keyboard shortcuts can no longer send a passphrase to the wrong board
None of this is scary while the app isn't in the store. That's exactly why the audit is happening now.
This morning there were seventy-two tests. Tonight there are a hundred and three.
🗳 Decisions nobody else gets to make
The audit marked some items "owner's decision — don't touch without him". There were six.
The cheat code came first.
The audit put it politely, but plainly: a hidden feature that changes what people pay for. A reviewer probably won't find it. But if one does, that's exactly what the store's rules punish.
There were two options. Keep only the lightning and drop the bonus. Or keep all of it and say so honestly in the notes for the reviewer.
I kept all of it.
I'm sure almost nobody reads an app's store description closely. So you can write about the cheat codes there plainly and clearly, and there's no problem.
The reviewer sees a feature they were told about. People don't get more than they should: it isn't unlimited, it's ten extra snippets. And it was made more for fun than for any deep purpose.
And anyone reading this diary already knows about it.
The second decision is my favourite.
The audit showed that a protected board could be deleted without confirming anything. Someone who got to the open app could simply wipe it. That's not safe, and it's a real hole.
The obvious patch is to ask for the vault passphrase. But here's what I thought about.
If you're holding the device, you're not some random person. You're its owner, or someone very close. So you should have the right to delete a board.
And there are plenty of reasons to. What's in there you don't need anymore. Or don't want to share. Or you've simply forgotten the passphrase — that happens all the time.
So deleting now asks for Touch ID. Not the vault passphrase — the fingerprint of whoever owns the Mac.
Before, there was no protection at all; now there is. And a forgotten passphrase no longer leaves you with a dead board you can neither open nor remove. Touch, delete, move on.
💬 A question
The audit deleted twice what it added, and the most valuable part of it turned out to be what it said not to touch. But I only have one question today — the one I started with.
The quick result is behind you; the real one is still far off. What keeps you in a project once it stops being quick? And have you ever quit when you realised it was going to be a long one?
Tell me how it goes for you 👇
After a busy Thursday I forgot to slow down, as usual. By Friday evening a third of the new limit is often gone already — the weekend evens it out. Today was one of those days: fifty-nine files in one pass.
And I have a nasty suspicion that that many changes at once don't go through without leaving a mark. Tonight I want someone who didn't write it to read it 😉