Live data from Hacker News

Meta outage

metastatus.com

881–890 of 902 posts

Re: Meta outage

#881

Earlier quoted context omitted.

exploded? the house... exploded? like, a gas leak or something?

Drug lab is more probable than a gas leak. Sources: https://www.statista.com/statistics/942043/laboratory-incide... - meth lab incidents are down to about 900/yr and have been far higher in the past (presumably because the labs have moved to things besides meth) https://rpgaspiping.com/blog/critical-safety-tips/gas-safety... (286 natural gas incidents per year) - I've tried to find a more credible source for this num…

> Drug lab is more probable than a gas leak.

I can’t tell if you’re trying to demonstrate the problem you have with your neighbors ;)

It was a gas leak, not a drug lab. The utility failed to fix things in a neighborhood where there’d been reports of leaks for years: https://www.wbur.org/news/2023/08/17/eversource-fine-gas-exp...

Re: Meta outage

#882

Earlier quoted context omitted.

I can imagine it being different in a city. I'm in a fairly quiet suburban area. One time I heard a loud boom. A few hours later I saw a neighbor outside and asked if he'd heard it and if he knew what it was. He told me a house a few neighborhoods over had exploded. I was a bit skeptical of it but he turned out to be right.

exploded? the house... exploded? like, a gas leak or something?

Yep. The utility had gotten reports of gas leaks on that street previously and didn’t fix it.

Re: Meta outage

#883
post #227

Earlier quoted context omitted.

I lament the fact error messages are rarely, if ever, displayed anymore. Just a generic message in its place, usually not even indicating whether it's a 'you' problem or a 'them' problem :(

Yeah, but at least it's a bit understandable that its changed in that direction, and usually you can get a developer-friendly error message if you look at the HTTP responses in the devtools. I remember one time a company I worked at received a support message where the title was (paraphrased) "DONT HURT MY CHILDREN" from some person who saw an error message saying something about "couldn't dispose of child" or someth…

You have to be careful with error messages. It's possible to give too much away and enable security vulnerabilities.

Re: Meta outage

#884
post #227

Earlier quoted context omitted.

Yeah, but at least it's a bit understandable that its changed in that direction, and usually you can get a developer-friendly error message if you look at the HTTP responses in the devtools. I remember one time a company I worked at received a support message where the title was (paraphrased) "DONT HURT MY CHILDREN" from some person who saw an error message saying something about "couldn't dispose of child" or someth…

You have to be careful with error messages. It's possible to give too much away and enable security vulnerabilities.

I'd assume the security vulnerability is there no matter what the error message says, but I guess very explicit and verbose error messages might expose details to make it easier to find said vulnerability.

Re: Meta outage

#885

And rather than an indication that it is not working, I was just told to login again; since the attempts were unsuccessful, I was led to reset my password. Now I have no clue if the password has been reset properly or an old one is used, or login with google is used, or if I will continue to be logged out after they fix stuff. If your service is down, please say "my service is down".

Password works on THREE other machines, fails completely on ONE.

I was logged in when the outage happened on machine A and phone B - immediately tried to reset password, which took me into the hellish abyss many of us are experiencing now...

This evening - about 18hrs about the event, I fire up machine C - it logs STRAIGHT INTO Messenger. OK... This is something, too scared to open a browser in case that triggers the session disconnect...

So I fire up laptop D - STRAIGHT INTO MESSENGER... OK, open browser, STRAIGHT INTO FB. Log into Google password manager, VISUALLY CHECK password, and it is my last known good password (in use at time of outage).

Fire up iPad E - Straight into Messenger!!! All these machines are on the same network!

Back to Machine A - clear cookies and try to log in, no joy; different browser and try to log in, no joy; try to reset password on this different browser (I might add, I did get a new Change password Token number off this attempt), but no joy; clear cookies and restart, then attempt to log in, no joy!

WHAT THE F?!?!?!?

I initially thought it may have been a 24hr block due to password change attempts? But now not so sure... I've also tried logging in on via Machine A in a VM from a different O/S to see if it may have something to do with it - but again no joy - this environment had NOT been logged in to FB before...

Thoughts????

Re: Meta outage

#886

And rather than an indication that it is not working, I was just told to login again; since the attempts were unsuccessful, I was led to reset my password. Now I have no clue if the password has been reset properly or an old one is used, or login with google is used, or if I will continue to be logged out after they fix stuff. If your service is down, please say "my service is down".

Password works on THREE other machines, fails completely on ONE. I was logged in when the outage happened on machine A and phone B - immediately tried to reset password, which took me into the hellish abyss many of us are experiencing now... This evening - about 18hrs about the event, I fire up machine C - it logs STRAIGHT INTO Messenger. OK... This is something, too scared to open a browser in case that triggers the…

MAC Address being flagged?

But on the flip side, I was able to create a back up profile in a different VM on this machine.....

Re: Meta outage

#887
post #868

Earlier quoted context omitted.

I think this argument falls flat on two axes: - in general, if the system is broken enough to be giving false-negatives on valid credentials, it's broken enough that there isn't much planning to be done here because the system's not supposed to break. So if they give me "Sorry, backend offline" instead of "invalid credential," they've now turned their system into an oracle for scanning it for queries-of-death. That's…

So your approach to security is to never admit that an application had an error to a user, but to instead gaslight that user with incorrect error messages that blame them? This is security by obscurity of the worst kind, the kind that actively harms users and makes software worse.

No. My approach to security is to never admit that an application had an error to an unauthenticated user.

That information is accessible to two cohorts:

- authenticated users (sometimes; not even authenticated users get access to errors as low-level as "The app's BigTable quota was exceeded because the developers fucked up" if it's closed source cloud software)

- admins, who have an audit log somewhere of actual system errors, monitoring on system health, etc.

Unfortunately, I can't tell if the third cohort (unauthenticated users) is my customers or actively-hostile parties trying to make the operation of my system worse for my customers, so my best course of action is to refrain from providing them information they can use to hurt my customers. That means, among other things, I 403 their requests to missing resources instead of 404ing them, I intentionally obfuscate the amount of time it takes to process their credentials so they can't use timing attacks to guess whether they're on the right track, I never tell them if I couldn't auth them because I don't recognize their email address (because now I've given them an oracle to find the email addresses of customers), and if my auth engine flounders I give them the same answer as if their credentials were bad (and I fix it fast, because that's impacting my real users too).

To be clear: I say all this as a UX guy who hates all this. UX on auth systems is the worst and a constant foil to system usability. But I understand why.

Re: Meta outage

#889

I wonder if this is related to 3 Red Sea data cables cut as Houthis launch more attacks in the vital waterway https://www.washingtonpost.com/business/2024/03/04/red-sea-u...

The cable cut only gonna after the arab world, or maybe india, but eropean to india communication don't depend on them that much so it's unlikelly, so probably not

Re: Meta outage

#890

Earlier quoted context omitted.

[flagged]

> do you really think there are masses of people who can’t tell the difference between a single sign on service being down and individual sites being down and reporting it to downdetector? Absolutely without a doubt. 99.9% of people don’t know what single sign on means or how it works. Sometimes I wonder what world HN lives in.

A world where people on HN are statistically extremely likely to be at least in the top 5% of the population in terms of skill at using a computer.

See also https://xkcd.com/2501/

Post reply on HN