There's a particular kind of software where the bug isn't an interruption. It's the product. You don't use it despite the crashes. The crashes are what you're using.
And you learn the workarounds before you learn the features.
Daniel sent us a prompt asking for five of the most spectacularly bug-ridden pieces of software ever released. Not good software with one disastrous patch. Not a rough launch that got smoothed over. Products where the bugs were so pervasive, so persistent, and so absurd that they became the user experience. Crashes, phantom data, elaborate workarounds, all just accepted as normal.
He wants the full picture for each one. What was it supposed to do. Why was it unreliable. The most extraordinary documented failures. How users coped. Whether anyone ever fixed it. And whether any of them became beloved anyway.
He wants both proprietary and open-source. Operating systems, games, obscure software. He specifically asked us to separate documented failures from internet folklore, and to not confuse bad design with actual bugs. And he wants a verdict at the end. Which one earns the dubious honour of being the buggiest software ever shipped.
It is. Because the moment you try to rank them, you have to decide what you're ranking. Frequency of failure? Scale of harm? How long it stayed broken?
Which is why the bad-design-versus-bugs distinction matters so much here. And Windows ME is the perfect place to start, because it's the one everybody names, and it's arguably the one that wasn't really a bug problem at all.
Explain.
Windows ME was the last version of Windows built on top of MS-DOS. Everything after it, XP onward, moved to the NT kernel. ME was the end of the line for the old architecture, and it was carrying both sixteen-bit and thirty-two-bit code at the same time, layered on each other. So a lot of what people experienced as instability wasn't a coding defect. It was the architecture buckling under itself.
So when people say Windows ME crashed constantly, they're describing a design failure.
Largely, yes. There were real bugs. Documented ones. But the foundation was the problem. And Microsoft made it worse with one specific decision. To make it boot faster, they restricted real-mode DOS. Which sounds like a technical housekeeping detail until you understand what real-mode DOS was for.
It was the escape hatch.
Technicians used to boot into DOS to troubleshoot, to replace a corrupt driver, to get at the filesystem when Windows wouldn't start. ME took that away. So you had a less stable operating system and fewer tools to recover it.
You removed the ladder and then made the floor more slippery.
That's the whole product.
What are the documented bugs, though? The real ones.
There are two big ones. First, System Restore. That was the flagship recovery feature, the thing that was supposed to save you. It turned out that snapshots taken after a certain date were being mis-date-stamped, which broke the recovery. Microsoft patched that one. Then there's a memory issue. Systems with more than five hundred and twelve megabytes of RAM could lose stability, and once you got past about one and a half gigabytes you could hit continuous reboot loops. That's documented under Microsoft's own knowledge base entry, KB three zero four nine four three.
Continuous reboot loops. So the machine wasn't just crashing. It was catching fire in a loop you couldn't interrupt.
And this is a home user in two thousand, who has just bought more RAM because more RAM is supposed to help.
The upgrade makes it worse. That's perverse.
PC World put it fourth in their Worst Tech Products of All Time list and gave it the nickname everyone remembers. The Mistake Edition.
Which only works in English.
The Dutch did better. Over there it was Windows Meer Ellende. More misery.
That's not a nickname. That's a review.
Here's the part I find most interesting, though. It was only on sale for four hundred and two days before XP replaced it. That's barely over a year.
XP arrived in October of two thousand one.
Correct. And for a product that short-lived, it generated an enormous amount of institutional memory. Every technician who worked in that window kept a DOS boot floppy. They stopped trusting System Restore entirely. They downgraded machines back to Windows ninety-eight as a matter of routine.
So users coped by reverting.
They coped by going backwards. The most reliable fix for the new operating system was the old operating system.
I want to dwell on that for a second, because it's such a strange shape for a fix. The official upgrade path is forward, and the actual working solution is backward. You buy the new thing, you discover it's worse, and the remedy is to reinstall the thing you already had.
And that's not a workaround in the normal sense. A workaround is a trick you use inside the software. This is a workaround that consists of not using the software.
It's an anti-workaround.
It's the user rejecting the premise. And the fact that it became routine tells you the product failed at the level of its reason to exist.
And did Microsoft ever fix it?
Partially. The System Restore bug got patched. The architectural instability never did, because you can't patch an architecture. It was solved by abandoning it. XP moved to the NT kernel and the whole class of problem went away.
Did it become beloved?
No. It's remembered with contempt. Though there was a review at the time, ActiveWin, that defended it and claimed you saw far fewer blue screens now. Which is one of those claims that's technically defensible if you measure the wrong thing.
Fewer blue screens. Just more of the machine rebooting itself in a loop forever.
Yes.
If Windows ME was a foundation problem, Sonic the Hedgehog in two thousand six was a different failure entirely. That was a game shipped unfinished because a holiday deadline mattered more than the game.
This is Sonic oh-six. Sonic Team and Sega, released on the Xbox 360 in November of two thousand six. It was supposed to be a franchise reboot for the fifteenth anniversary. Big deal for them.
So what went wrong?
The timeline collapsed. Yuji Naka, the series co-creator, resigned in March of that year. The team got split, because they were also making Sonic and the Secret Rings for the Wii. And Sega insisted it had to ship for the two thousand six holiday season.
There's always a holiday.
And the producer, Takashi Iizuka, said it plainly afterwards. We didn't have any time to polish and we were just churning out content as quick as we could.
That's a confession with a press release attached.
And it's not even the worst version of it. The reporting is that Sonic Team rushed the final stages, ignoring control problems and bug reports that were coming back from Sega's own quality assurance department.
They ignored their own testers.
They didn't have the schedule to act on them.
Those aren't the same thing, but the result is.
The result is the same. Metacritic score of forty-six on the Xbox 360, forty-three on the PlayStation 3. Eurogamer called the camera the worst they had ever seen. GameSpot's verdict was that it was a mess from top to bottom.
And this is Sonic. Sonic is fast movement through complex geometry. The camera is not a nice-to-have in that game. The camera is half the game.
Which is why the reviews were so harsh. The thing that made Sonic Sonic is the thing that didn't work.
What's the most extraordinary documented failure?
I think it's the review saga. Play Magazine, Dave Halverson, gave it a nine point five out of ten. Nine point five.
For that.
He was told the glitches wouldn't ship. So he downgraded to eight point five on that understanding. Then the glitches did ship. And when he reviewed the PlayStation 3 version, knowing they hadn't been fixed, he gave it five point five.
So the reviewer was lied to, and the correction is visible in public.
In public, in sequence. It's one of the cleaner records of a game shipping with known defects.
Did they ever patch it?
No. The glitches were never fixed. Sega delisted it in twenty ten, and the cited reason was the sub-average Metacritic score. They pulled their own anniversary game from sale because of how it reviewed. It came back on the Xbox 360 marketplace in twenty twenty-two.
How did users cope?
They didn't, in the sense of finding a workaround. There's no workaround for a camera. They coped by making it a joke.
That's a real coping mechanism.
It's a genuine one. It became one of the most-watched games for glitch showcases. Let's Play channels built whole series out of it. There was a live fandub in twenty nineteen that became its own thing. And the official Sonic account on social media has mocked the game.
The company joined in on the joke about their own anniversary product.
Eventually. Once it was old enough to be funny.
It's worth naming what that coping mechanism actually is, though, because it's not trivial. Turning a broken product into a shared joke is a way of taking ownership of it. The company lost control of the narrative, the players picked it up, and the game's failure became the community's material.
They converted the defect into culture.
Which is a very different outcome from what happens when the software is holding something that matters.
Sonic oh-six was rushed. Big Rigs was something stranger. That one shipped in what its own producer believed was a pre-alpha state.
Big Rigs, Over the Road Racing. Stellar Stone as developer, GameMill publishing, November two thousand three. It was a truck racing game, sold exclusively through Wal-Mart.
A truck racing game, sold in the truck aisle.
Sold exclusively through one retailer. It was outsourced to a Ukrainian team, and the producer, Sergey Titov, has said he believed it shipped in a pre-alpha state. Meaning he did not think it was finished.
He didn't think it was finished, and it was on shelves.
On the shelves. Here's the list. There's no collision detection. Trucks pass through opponents and through the scenery. The opponent never moves. The opponent car sits there. You race against a stationary object.
And you can still lose?
You can still lose, because there's no time limit, so you can sit there forever. But the opponent does not move. There's no police in the game, despite the box promising police chases. If you select the fourth route, the game crashes. And if you drive in reverse, you accelerate indefinitely.
Reverse is the fast direction.
Reverse is faster than forward, and it has no upper limit.
So the optimal way to play a truck racing game is to drive backwards forever until you exceed the concept of speed.
And when you win, the trophy reads, in full, all caps, YOU'RE WINNER, space, exclamation mark. With the space before the exclamation mark.
You're winner. That is the most efficient possible summary of the entire product.
Metacritic score of six out of one hundred. That's the lowest ever recorded. It started at eight, from five reviews, and then more reviews came in.
It got worse as more people looked at it.
GameSpot's Alex Navarro gave it one out of ten and described it as almost completely broken and blatantly unfinished in nearly every way. And then he called it as bad as your mind will allow you to comprehend.
That's not a review. That's a diagnosis.
Sergey Titov offered to replace anyone's copy with any Activision Value title. Twenty people took him up on it.
Twenty.
Twenty. But here's where it turns. It's got a real cult following. There's a fansite dedicated to it. It was exhibited at the NYU Game Center as part of a show called Bad Is Beautiful. And in April of twenty twenty-five, it was re-released on Steam with a version one point zero patch.
Twenty-two years later.
Twenty-two years later, and the patch does one thing. It finally makes the opponent move.
They fixed the opponent. After twenty-two years.
That's the patch.
So did they fix it? Sort of. In twenty twenty-five.
In twenty twenty-five, partially, and only the one thing that everyone had been laughing about for two decades.
Windows ME was arguably design. Big Rigs was unambiguous code. That's the distinction Daniel asked us to hold onto.
Big Rigs is a coding defect from top to bottom. There is no architecture excuse. The collision detection simply isn't there. It was never written.
Those three are the famous ones. The next two are where this gets darker, and stranger.
Jet Set Willy. Software Projects, ZX Spectrum, March of nineteen eighty-four.
Manic Miner's sequel. Manic Miner is one of the canonical British platformers, and Jet Set Willy was the follow-up, and it was the best-selling home game in the UK that year.
It sold enormously. And on release, it was impossible to complete.
Not difficult. Impossible.
Impossible, because of what players named the Attic Bug. There's an arrow sprite in one of the rooms. It travels past the end of the video memory it's supposed to stay inside, and when it goes past the boundary, it starts overwriting the game's own data. Rooms get corrupted permanently. You cannot finish the game.
The arrow escapes its own room and edits the level.
That's exactly what it does. And the response from Software Projects is the part that should be taught. Initially, they said it was intentional. The corrupted rooms were poison gas rooms. A feature.
Poison gas.
Then they recanted and issued POKEs to fix it.
A POKE is a direct memory write. On that hardware you could patch a game by typing instructions into memory before running it.
Publish the fix in a magazine, readers type it in, and the game becomes completable.
So the fix is distributed by handwriting.
Via magazine listings. And the completion competition was already running. Two players, Ross Holman and Cameron Else, actually finished it, and they supplied bug fixes as part of it. Cameron Else ended up being hired to port the game.
The users became the quality assurance team. The winners of the competition were essentially the only functioning QA department the product ever had.
And that's not the end of it. The BBC Micro port, the Commodore sixty-four port, the Atari eight-bit port, the Dragon thirty-two port. Every one of those was also impossible to complete, for different reasons.
Different bugs in each version.
Different reasons entirely. Each port broke in its own way.
That's the detail that gets me. It's not one bug that got copied across. It's a fresh impossibility on every platform. Which tells you the underlying code was so fragile that the act of moving it to new hardware introduced entirely new ways to fail.
The same game, broken five different ways.
And despite being literally unfinishable on release, what happened to it?
Retro Gamer readers voted it the sixth best game of all time in two thousand four.
Sixth best game ever. A game that could not be completed on the hardware it shipped on.
That's the paradox. The design was good enough that people forgave the fact that it was broken, and rebuilt it themselves.
Jet Set Willy was impossible to finish. Horizon was impossible to survive.
The Fujitsu Horizon system. Live with the UK Post Office from nineteen ninety-nine to the present. It was point-of-sale accounting software. It tracked the money coming in and out at post office branches.
And it invented money.
It invented debts that didn't exist. There are specific, named bugs. The Callendar Square bug, also called the Falkirk bug, created duplicate transaction entries. The Dalmellington bug meant cancelled transactions stayed in play. And the REMM IN bug, where a subpostmaster hitting the previous key to double-check a recorded cash receipt would record it multiple times.
So looking back to make sure you got it right is what creates the phantom debt.
Hitting previous to verify. The act of checking is what breaks it.
That is a cruel bug. The instinct to double-check is the thing that destroys you.
Justice Peter Fraser found that Horizon contained bugs, errors and defects, and that Legacy Horizon, the version running from two thousand to twenty ten, was not remotely robust. Those are the words of the judgment.
Not remotely robust. That is a judge being polite and being devastating at the same time.
David McDonnell, a developer who worked on it, testified that it was beyond anything he'd ever seen even in the twenty-five to thirty years since that project. He said it was a mess.
Twenty-five to thirty years in software and this was the worst.
The scale of it. Between nineteen ninety-nine and twenty fifteen, more than nine hundred subpostmasters were wrongfully convicted of theft, fraud, or false accounting, based on Horizon data. Two hundred and thirty-six went to prison. The scandal is linked to at least thirteen suicides.
Thirteen people dead because the software said the money was missing.
Because the software said the money was missing, and the software was believed over the people.
How did users cope?
That's the problem. They couldn't. There's no workaround for a criminal conviction. The workaround, for years, was to pay back money you didn't owe to make it stop. To accept a shortfall that the system invented, and cover it out of your own pocket, because the alternative was prosecution.
So the coping mechanism was to absorb the damage personally.
That's the coping mechanism. And the Post Office spent years insisting the system was robust. Same structure as the poison gas rooms. The system is fine, you're the problem. Except here it ran for two decades and put people in prison.
Did they fix it?
The two thousand nineteen High Court case settled for fifty-eight million pounds. The claimants netted about twelve million after costs. Final compensation is expected to exceed a billion pounds.
Twelve million to the people, out of a fifty-eight million settlement. The costs ate most of it.
Most of it. And the system is still in use.
Still in use now.
Still in use, described as full of patches. It was never replaced.
And that gets us to the verdict, and I want to do this properly rather than just declaring a winner. There's no actual award for buggiest software ever shipped. No body certifies this.
It's a rhetorical honour.
So we should say what we're measuring. Frequency of failure, scale of harm, how long it stayed broken, and whether the bugs were the product itself or a defect within the product.
Four criteria.
Four. So let's apply them. Herman, make the case for the one you'd argue.
I'd argue Horizon, and I want to be clear that I'm not doing this for the obvious reason. Anyone can point at a miscarriage of justice and call it the worst.
Then why?
Because on the frequency criterion, it wins. Nine hundred and thirty-seven convictions by twenty fifteen. Somewhere around a thousand known cases per year by the end, in thousands of branches, running every day, for over two decades. That is not a bug that happened. That is a bug that was the operating condition.
And on scale of harm it's not close.
It's not close. Two hundred and thirty-six people lost their liberty. Thirteen lost their lives. The compensation will cost more than a billion pounds. No video game can compete with that, and I don't think we should pretend otherwise.
But the criteria pull apart from each other, and that's the interesting part. Because on the fourth criterion, whether the bugs were the product, Big Rigs has a real case.
Go on.
The lowest Metacritic score ever recorded. Six out of one hundred. No collision detection. An opponent that doesn't move. A route that crashes. Reverse as the acceleration vector. This is a game where the brokenness is not a flaw within the product. The brokenness is the entirety of the product.
It shipped in what its own producer called a pre-alpha state.
Its own producer. And then there's Windows ME, which fails on a different axis. It fails the bug criterion entirely and still makes the list, because the architecture was the defect. It sold for four hundred and two days. Four hundred and two days, Herman.
And there's no formal calculation for that.
There isn't. But four hundred and two days and a knowledge base article about reboot loops is a strong résumé.
You're not going to pick Big Rigs.
I'm not going to pick Big Rigs, and I'll tell you why. I've been sitting here trying to construct the argument and it keeps collapsing on one point, which is that the harm requirement keeps coming back into the room.
Say it.
You can put the controller down. That's the whole difference. With Sonic oh-six, with Big Rigs, with Jet Set Willy, you can put the thing down and walk away and the world continues. With Horizon, there is no putting it down, because the person who would be putting it down is the person who is being prosecuted for theft.
The user can't exit.
So Horizon wins, but I want the verdict stated precisely, because it's not a verdict about bugs. On the narrow reading, where I'm ranking sheer quantity and absurdity of defects, it's Big Rigs. On the honest reading, where I'm asking which product's bugs did the most damage, it's Horizon, and there's no second place.
I'll take that. And there's something underneath all five that I keep coming back to.
Which is that the same phenomenon produces opposite results depending on what the software was responsible for.
That's it. A truck racing game that doesn't work is a meme. Accounting software that invents phantom debts is a prison sentence. Same class of defect. Same pervasiveness, same persistence, same absurdity. Totally different consequence.
And the difference is entirely in what the thing was holding on behalf of its users.
Entirely. Which means the word "bug" is doing two jobs in this episode. It describes a defect, but it also describes the scope of the thing it was allowed to touch. And those two jobs get confused constantly.
Which raises the question we haven't answered. Why does the same failure get comedy in one case and catastrophe in the other, and who decides which one you got?
The person who decided how much power to hand the software.
Windows ME, Sonic oh-six, Big Rigs, Jet Set Willy, Horizon. Five for five.
Sonic oh-six, does it hold up as a candidate? I want to press on this one because I think it's the weakest.
Why?
Because at least part of the fix was possible. Titov offered replacements. Software Projects issued POKEs. Microsoft patched System Restore. Horizon never actually got fixed. It's still running, full of patches, right now.
That's the difference you want to make.
The only bugs that never got fixed were the ones nobody was being prosecuted for. That's backwards. The one that put people in prison is the one that never got replaced.
Sonic oh-six sold eight hundred and seventy thousand copies. Half a million units of a ninety-two pound experience and a full price sticker on a game its own team had no time to polish. That is not an obscure failure. That is a failure that went to scale.
And it never got patched. So the scoreboard is: Big Rigs got its patch twenty-two years later. Windows ME got superseded by XP. Jet Set Willy got POKEs from magazines. Sonic oh-six got nothing. Horizon got fifty-eight million pounds and a billion pounds more to come, and is still doing the same job now.
That's the whole list.