7 ms·
It logged me out and told me that my credentials were incorrect; I thought my credentials had been stolen, so I'm kinda personally glad that it seems to be happ
by jonnycomputer 3y ago
It logged me out and told me that my credentials were incorrect; I thought my credentials had been stolen, so I'm kinda personally glad that it seems to be happening to a lot of other people too. I know that's a bit selfish, but :shrug:
- MyFirstSass 3y agoSame, thought all of my friends were getting spammed and i'll look like a "boomer" who got phished. Then i remembered i have a very long and secure password, then immediately panicked about someone having access to my Gmail. The sense of security is more brittle than i thought.
- sandspar 3y agoOn a psychological note, I think the threat detection part of our brain doesn't always notify our conscious thought that it's actively monitoring for threats. I've often noticed that when I'm carefully handling a hot frying pan then my ringing phone is more likely to startle me than usual.
- fuzzfactor 3y agoWhen you've already got one threat on your hands you're less prepared for anything else.
- sandspar 3y agoThat makes sense. I've noticed too that my brain seems to have a threat pre-emption module as well as a threat reaction module. For example, I'll sometimes be walking and texting at the same time, only to stop in my tracks and suddenly realize that there's a hidden stair in front of me.
- 101008 3y agoI panicked the same. Even when I tried to recover my password, it said my email address wasn't associated to any account. I thought I lost it forever
- marcosdumay 3y agoThat's the natural endgame of the "user-facing services must not stop, if something they depend upon stops, they must only degrade" philosophy.
- lanstin 3y agoI heard for a while Netflix would fail open if auth was unavailable. Like it’s just movies just let em see it. Facebook data is more sensitive. Not so much the data people go there to see, cool memes that their friends liked, but the list of friends and interests. Other places I worked had the ability for Ops to push out a change saying the site was down for maintenance. After a while we stopped using it and just took the hit of a bunch of 5xx errors. Basically when the planned down times became shorter than the time to propagate the down setting.
- marcosdumay 3y agoFailing open is maybe ok. Telling everybody on the world their account doesn't exist anymore isn't.
- kortex 3y agoSame same. I went through the password reset flow (I was overdue anyways), it never sent anything to my SMS, so I did it again with email, reset the password and went to log in with the new password, "Incorrect password" error. Old password, also incorrect. Didn't help that I had just posted a lukewarm spicy take on how linguistic prescriptivism is BS. All the while the website felt like it was unstable, hard to describe, but it felt like it was bouncing around between URLs too much and reloading a lot. Definitely feels like a botched update on their end. E: Instagram is misbehaving as well, banner loads but big "Something is wrong" error on the feed. E: now youtube has "Something went wrong" - WTF. I can't believe I'm saying this, but thank goodness for reddit and X[itter]??? E: interesting, seeing a big spike across multiple platforms on downdetector, including AWS: https://downdetector.com/status/aws-amazon-web-services/ https://downdetector.com/status/aws-amazon-web-services/ I'm not able to log in right now, but that could be PEBCAK, I have too many saved IDs and I don't want to fail2ban myself
- pratnala 3y agoThe password reset flow was broken too. And I got logged out on every device. My friend who works there said they can't login either.
- cratermoon 3y agoDiscord is also having issues.
- samaritano 3y agodowndetector reports has gone down but to me is still bugged out, been catching a livestream on youtube all along though, meta stocks are back up from the dip so I take it some regions are restored to normality
- NikolaNovak 3y agoYes. My spidey sense went off and I told my work I'll be off for an hour while I redo all my passwords... might still do that but glad to know it's not necessarily me getting hacked.
- pratnala 3y agodon't bother. fb's forgot password flow is broken too.
- nathanaldensr 3y agoAs was the account hijack process. It just loops.
- smcl 3y agoI called out some comment for being racist a little earlier (yeah I know, just report and move on...) and figured they'd managed to pwn my account somehow. Good to know it's not just me.
- fishnchips 3y agoStrictly speaking, just because there's an outage does not mean you're not pwn'ed.
- darkwater 3y agoMaybe the outage happened because they used a 0-day to pwn smcl
- fishnchips 3y agoCrazier things have happened.
- smcl 3y agoIn an "anything's possible" sense then yeah. But the fact that FB was not letting me login with the credentials I knew to be correct was directly attributed to a global outage, rather than a me-specific issue. Which I can now verify by checking the devices that are authorised to my account.
- DonHopkins 3y ago[flagged]
- ReptileMan 3y agoMuch better defense if someone accuses you of racism - you still have not shown that I am wrong.
- DonHopkins 3y agoSo you're saying you do own your racism. Well good for you, one of the brave racists -- now we know what kind of a person you really are. But it doesn't mean you're right, it just means your opinion is worthless and you're not worth debating because you're an intellectually dishonest bigot, even worse for believing in scientific racism. Edit: Your beloved scientific racism is not reality, it's a pseudoscience, as foolish and wrong as Astrology and Phrenology and Homeopathic Medicine. You're still a intellectually dishonest bigot. If you're so intellectually honest and sure of yourself, then why don't you state right now unequivocally for the record that you're an unrepentant racist bigot? https://en.wikipedia.org/wiki/Scientific_racism https://en.wikipedia.org/wiki/Scientific_racism Scientific racism, sometimes termed biological racism, is the pseudoscientific belief that the human species can be subdivided into biologically distinct taxa called "races", and that empirical evidence exists to support or justify racism (racial discrimination), racial inferiority, or racial superiority. Before the mid-20th century, scientific racism was accepted throughout the scientific community, but it is no longer considered scientific. The division of humankind into biologically separate groups, along with the assignment of particular physical and mental characteristics to these groups through constructing and applying corresponding explanatory models, is referred to as racialism, race realism, or race science by those who support these ideas. Modern scientific consensus rejects this view as being irreconcilable with modern genetic research. Scientific racism misapplies, misconstrues, or distorts anthropology (notably physical anthropology), craniometry, evolutionary biology, and other disciplines or pseudo-disciplines through proposing anthropological typologies to classify human populations into physically discrete human races, some of which might be asserted to be superior or inferior to others. Scientific racism was common during the period from the 1600s to the end of World War II, and was particularly prominent in European and American academic writings from the mid-19th century through the early-20th century. Since the second half of the 20th century, scientific racism has been discredited and criticized as obsolete, yet has persistently been used to support or validate racist world-views based upon belief in the existence and significance of racial categories and a hierarchy of superior and inferior races.
- suyash 3y agome too, also Instagram, could be that Facebook got hacked ?
- suyash 3y agoPro tip: in chase meta actually got hacked, it would be good idea to not use that password on any other websites, change them immediately.
- mfrommil 3y agoA much better UX would be clear error messaging informing users that the service is down and there is no problem with their individual account. This would prevent people from panicking they've been hacked and/or unnecessarily resetting their password.
- eurekin 3y agoThere was for a brief moment. I got that once
- Kalium 3y agoYou are absolutely correct. That would be a much better experience. That said, getting there strikes me as pretty challenging. Automatically detecting a down state is difficult and any detection is inevitably both error-prone and only works for things people have thought of to check for. The more complex the systems in question, the greater the odds of things going haywire. At Meta's scale, that is likely to be nearly a daily event. The obvious way to avoid those issues is a manual process. Problem there tends to be that the same service disruptions also tend to disrupt manual processes. So you're right, but also I strongly suspect it's a much more difficult problem than it sounds like on the surface.
- matsemann 3y agoBut there's something off here. I wouldn't expecting to be shown as logged out when the services are down. I'd expect calls to fail with something aka 500 and an error showing "something happen edited on our side". Not all the apps going haywire.
- Kalium 3y agoAt the scale of Meta, "down" is a nuanced concept. You are very unlikely to get every piece of functionality seizing up at once. What you are likely to get is some services ceasing to function and other services doing error-handling. For example, if the service that authenticates a user stops working but the service that shows the login form works, then you get a complex interaction. The resulting messaging - and thus user experience - depend entirely on how the login page service was coded to handle whatever failure the authentication service offered up. If that happens to be indistinguishable from a failure to authenticate due to incorrect credentials from the perspective of the login form service, well, here we are. At Meta's scale, there's likely quite a few underlying services. Which means we could be getting something a dozen or more complex interactions away from wherever the failures are happening.
- Twirrim 3y agoLikewise, started password reset process that won't complete, asked my wife to double check my account wasn't compromised and posting cryptocurency crap or somesuch.
- KMag 3y agoYea, the wife came to me in a bit of a panic that her Facebook account got hacked. I tried logging in to FB to check if I had been unfriended, and I also got errors indicating my password was incorrect. My FB password is 96 bits from /dev/urandom in a GPG-based password manager I wrote for myself a couple decades ago. So, no my password wasn't wrong, and I'm not a big enough target for someone to put enough effort into figuring out how to snarf up my password data and crack my GPG passphrase. Anyway, when FB thought my password was wrong I calmed way down. I thought maybe FB corrupted their password DB or something, so I just tried to reset my password, got into an odd workflow loop, and then quacked "downdetector facebook".
- sigil 3y ago> My FB password is 96 bits from /dev/urandom in a GPG-based password manager I wrote for myself a couple decades ago. We have the same approach to password management!
- ambichook 3y agothat's actually really cool, i hadnt considered writing my own password manager but i feel like it'd be a fun and fairly useful project, did it take you particularly long to do? i'm interested in giving it a go :D
- KMag 3y agoThe heavy lifting is done by GPG in a subprocess, taking information on stdin or outputting the decrypted data on stdout. The rest is just generating the passwords, organizing the encrypted files, and perhaps interacting with the clipboard. Have a look at https://www.passwordstore.org/ https://www.passwordstore.org/ and also https://github.com/kmag/store_password_gpg https://github.com/kmag/store_password_gpg
- alkonaut 3y agoYeah your product should NEVER confuse an auth service being down with a failed auth. This is really terrible by FB.