Now Resolved: FB iOS SDK Outage Causing Disruption to 3rd Party iOS Apps
developers.facebook.com
developers.facebook.com
Moreover, the actionable advice to upgrade the SDK is a complete non-technical non-sequter seemingly put as a distraction:
- They admit it was a server side change that caused the crashes. SDK version doesn't change that.
- No breakdown of which versions were affected (or was it everything?).
- Is a newer release safer? Were changes made that we would get by upgrading?
Did anyone by chance MITM the server payload to understand the bad code/bug?
> This is the second similar incident this year. We want to apologize for the inconvenience these events have had on our developers and their users.
It’s an odd addendum to put in and appears ominous to me.
There are many similar successful concepts that cap the maintenance window that services must tolerate, while at the same time giving developers enough forewarning to understand what is expected of them.
My understanding is that to use Facebook as an auth mechanism, you must use their SDK (and personal data vacuuming along with it), so dropping Facebook auth would allow apps to drop the SDK, which would be a win for both privacy advocates and users who enjoy their apps working even when Facebook breaks something.
Does anyone know more about this?
As far as I remember Facebook does support being and openid connect authentication provider so it should be theoretically possible without their SDK. But it might be that they put some practical restrictions in place to force usage of their API??
The crash was just that a dictionary decoded from json sent by the server contained null in a place where the code expected a non-null value. The actual payload difference would not be very interesting.
I believe the audience is marketing and management.
What did they learn, exactly? There wasn't a postmortem on the prior incident, and it would seem that no postmortem is planned for this incident, either.
https://github.com/facebook/facebook-ios-sdk/issues/1385#iss...
There is no shame for a bad config push... it happens... but there’s a huge amount of shame in having an ego so big you cannot admit it.
Agreed on your second point as well.
That's fine for a social network, but by forcing the SDK to be directly integrated into third party apps, they're forcing their attitude onto developers that have a "move slowly and don't break things" attitude.
I'm shocked that they have this rule, that developers play along, and that there's apparently nothing that can be done about this.
If there was some easy way to find out which iPhone apps that I'm using have the FaceBook SDK installed, I would mercilessly uninstall all of them.
But as a consumer, I'm completely blind to the privacy-violating malware that is being forced upon me by faceless corporations.
Yay.