4 ms·
There are quite some harsh comments here below. You can't plan for every possible failure point, who knows what part of a system/infra out of everything that th
by mns 3y ago
There are quite some harsh comments here below. You can't plan for every possible failure point, who knows what part of a system/infra out of everything that they have went down and triggered this behaviour. Some things you just can't catch/predict. Especially in huge systems like theirs. I would expect people here to understand things like these and not just call people names for something like this, we all know things seem simple/clear from the outside, but the job of debugging and fixing something like this take quite some effort.
- anigbrowl 3y agoThis is a company with one of the largest digital infrastructures in the world. An outage is understandable, inability to tell they're having an outage and inform users appropriately is not. Stop making excuses for people who are literally awash in resources.
- dylan604 3y agoIt is always better for the company's rep for the issue to have been on your end. Admitting fault comes with a potential liability. It's gaslighting written as an SLA
- edanm 3y ago> Stop making excuses for people who are literally awash in resources. This is a pretty weird outlook to have - looking at any group awash with resources, whether it be governments or other companies, and you can clearly see that even with those resources, failures still happen. You can jump up and down and pretend that this is solvable, or you can look at reality, look at all the evidence of this happening over and over to almost everyone, and conclude with some humility that these things just happen to everyone. (Looking this reality in the face is one of the things motivating my beliefs around e.g. AI safety, climate change, etc.)
- anigbrowl 3y ago> An outage is understandable
- deleted 3y ago[deleted]
- shkkmo 3y agoYou can't plan for every contigency, but you can reserve potentially scary message for situations where you know they are correct. An unpected error state should NOT result in a "invalid credentialiald error".
- shadowgovt 3y agoThis is the nature of credentials errors. The more information you give, the more you're telling an untrusted and therefore assumed-hostile agent. I hate it because it's bad UX, but that's the thinking behind it.
- shkkmo 3y agoPushing people to unnecessarily reset credentials increases risk. Not only does it increase acute risk, but it also decreases the value of the signal by crying wolf. The argument here is the kind of nonsense cargo cult security that pervades the industry.
- shadowgovt 3y agoI think this argument falls flat on two axes: - in general, if the system is broken enough to be giving false-negatives on valid credentials, it's broken enough that there isn't much planning to be done here because the system's not supposed to break. So if they give me "Sorry, backend offline" instead of "invalid credential," they've now turned their system into an oracle for scanning it for queries-of-death. That's useful for an attacker. - in the specifics of this situation, (a) credential reset was offline too so nobody could immediately rotate them anyway and (b) as a cohort, Facebook users could stand to rotate their credentials more often than the "never" that they tend to rotate them, so if this outage shook their faith enough that they changed their passwords after system health was restored... Good? I think "accidentally making everyone wonder if their Facebook password is secure enough" was a net-positive side-effect of this outage.
- shkkmo 3y agoSo your approach to security is to never admit that an application had an error to a user, but to instead gaslight that user with incorrect error messages that blame them? This is security by obscurity of the worst kind, the kind that actively harms users and makes software worse.