Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. I Perfected My "Lapdock" [video] (youtube.com)
    —discuss
  2. Show HN: Noise – Static Noise for Focusing (ryan-schachte.com)
    —discuss
  3. Secret Silicon Valley 'Sex Misconduct List' with 100 Men Warns Female Workers (techtimes.co.uk)
    —discuss
  4. PicnicTasks – A no-setup task manager for people who hate project management (picnictasks.uk)
    —discuss
  5. AI is turning the world into slop (spectator.com)
    —discuss
  6. PageIndex Emerges as Vectorless RAG Alternative for AI Retrieval (x.com)
    —discuss
  7. Perplexity's AI Sandbox Blocks All Escape Attempts in Red-Teaming Tests (x.com)
    —discuss
  8. Oura Postpones IPO (bloomberg.com)
    —discuss
  9. Jev Civilizations (github.com/jonessteven)
    1comments
  10. Fuck Adobe – Free vector editor (dadaki.com)
    1comments
  11. How AI Is Changing the Role of Legal Intake Specialists (legalcareerpath.com)
    —discuss
  12. An AI lab Tycoon game (claude.ai)
    1comments
  13. Metatherian Origin in the Early Cretaceous (mapress.com)
    —discuss
  14. Proof that puzzles can reverse cognitive impairment (southampton.ac.uk)
    —discuss
  15. New Cyber-OSINT model released (twitter.com/0x0sojalsec)
    1comments
  16. Needle in the hay in the style of Claude Monet (bygeorge.fun)
    —discuss
  17. Leaked Gemini 4 Pro Benchmarks Signal Google's Return to the Top of AI (nokiapoweruser.com)
    —discuss
  18. Google to end ChromeOS, support transition to Googlebook OS (tomshardware.com)
    —discuss
  19. MCP Python SDK OAuth flaw enabled account takeover (cycode.com)
    —discuss
  20. SentriSend – Outbound email security gateway to prevent SES bounce bans (sentrisend.com)
    —discuss
  21. The SaaSpocalypse That Wasn't, with Atlassian CEO Mike Cannon-Brookes (theverge.com)
    —discuss
  22. Mac Mini M6 Review (theguardian.com)
    —discuss
  23. Muse gives out your home address without telling you (theguardian.com)
    —discuss
  24. Firefox 157 released with 'biggest visual refresh in years' (omgubuntu.co.uk)
    1comments
  25. NASA Asked Several Former SR-71A Blackbird Staffers to Help Secret Restart (aviationweek.com)
    —discuss
  26. Why the Bronze Age Collapsed (worksinprogress.news)
    —discuss
  27. Grev – Thinking Coreutils (github.com/aurorainfra)
    —discuss
  28. Show HN: I built another screen recorder for Mac (ascreenrecorder.com)
    1comments
  29. Show HN: JBR-001 – An open-source 3D printable desktop robot (arduino.cc)
    —discuss
  30. Chatting App from Future Generation (vercel.com)
    3comments

Firebase SDK is CRASHING ALLLL iOS Apps, since today morning

82 pointsby 2h agotwitter.com
43 comments
1h agoHN ↗

Resolved, but can still affect customers for up to 4 hours...

So many problems here, and no signs of an updated SDK that behaves properly on malformed input.

1h agoHN ↗

This is not the first time this has happened.

1h agoHN ↗

I was wondering why random apps kept crashing today. Good to know.

1h agoHN ↗

But this is completely not acceptable from the Google

1h agoHN ↗

They’ve been accepting this for years and so have users

1h agoHN ↗

Ugh.

That's the dark side of these types of dependencies.

But they provide a great deal of utility, so I can understand the attraction.

1h agoHN ↗

I guess it's time Apple sherlocked Firebase.

17m agoHN ↗

Apple's web services are shit, so I hope not. When it works it's great/okay, but when it breaks 5-10% of the time there's absolutely no indication what the hell is going on. Apple's allergic to progress indicators and useful error messages.

1h agoHN ↗

I'm hearing an awful lot of "How could they do this to us?" and not a lot of "Wow, maybe we should have read some of this 3rd party code we bundled into 'ALLLL' of our apps"

Just an ignorant and naive outsider's take, but to me it paints a pretty damning picture of the state of mobile development.

1h agoHN ↗

Mobile and frontend development, both, now-a-days contain way way way more dependencies than they should.

1h agoHN ↗

Yes, but the SaaS adoption is also the reason. Many analytics SDKs, observability tooling etc.

1h agoHN ↗

maybe we should have read some of this 3rd party code we bundled

Not really practical though, if you push the thought to its limit. That 3rd party code is literally everything that's not written by you, from firmware to the launch UI. And if you don't push the thought to the limit then there's always that risk leading to the same "maybe we should've read X" if something happens in X. Trusting that others will be good stewards of all that 3rd party stuff is a hard requirement for making progress.

51m agoHN ↗

I agree its not practical, but including any 3rd party libraries in your project puts it at real risk of upstream bugs. There needs to be acceptance of this rather than blame culture.

1h agoHN ↗

You're already trusting them with their proprietary cloud products, whose code you can't read. Why wouldn't you trust them with their client SDK code.

54m agoHN ↗

Because their client SDK might crash the entire app if the server does something funky. We saw it before with Facebook, and now it's Firebase's turn.

A dependency on code you can't read reaching out to servers you don't control is a recipe for disaster. If you can control the server, you can try to add fixes, redirect DNS to a backup cluster, you name it. If you implement the client, you can write the code in a way that doesn't cause full crashes when the remote server does something weird. If you can do neither, you're handing over your business flow and uptime to a third party that doesn't care about you in the slightest.

1h agoHN ↗

I remember first learning about Firebase when working on Android push notifications, a loooooong time ago (~2011 i think). Over time it grew into this full-featured app development platform, after an aquisition (don’t remember the name).

These days however it feels a bit neglected, and somehow poorly bolted on to GCP. I still have a few production apps running on it and news like this reinforces my belief that it’s in decline.

What are folks using these days that (ideally) is open source and self-hostable? I don’t want to lock in with another platform. Some of these apps use the offline sync feature of Firestore (apps used in basements and other low-connectivity areas).

1h agoHN ↗

I guess Supabase is the obvious contender. It doesn't provide the actual frontend hosting though, which is a bit of a pain because now you have two problems.

24m agoHN ↗

I wasn't aware that Supabase is self-hostable - thanks for pointing that out, will have a look. Customer is in Europe, if they decide to move away from Firebase, they don't want to migrate to another managed platform run by a US company (digital sovereignty etc.)

1h agoHN ↗

Especially for offline sync Firebase is still much stronger than other all-in-one solutions.

The real alternative there would be to use some SQLite syncing solution and a different solution for auth and cloud compute.

32m agoHN ↗

While Firebase has support for queries with realtime updates and offline caching, I wouldn't quite call it offline sync.

59m agoHN ↗

Yes that's the sad part, if you want to integrate Push Notification in your app, and you want to use a 3rd party vendor like OneSignal etc, you still need a fuckin FIREBASE account & FIREBASE dependencies in your app. So every app on the Play Store comes with firebase dependency.

24m agoHN ↗

Calling them a 3rd party push notification vendor is being generous. Google is still doing the push notification and I guess OneSignal offers a wrapper around the libs.

1h agoHN ↗

If only there was any way to avoid this, right..? (I don't mean from Google's side, that as well, but that's not the point)

48m agoHN ↗

No, not under your control. It is like "trust me bro" thing from your dependency maintainers.

1h agoHN ↗

Keep vibe coding and breaking everything.

This will be the new normal as all human “engineers” from staff to seniors are now down levelled to interns and junior engineers when using AI; unable to understand what they are doing and pushing broken updates like this into production with “agents”.

Better not blame Claude on this outage.

59m agoHN ↗

No matter who writes the code, the name in the commit is responsible as well as the person who approved / reviewed the PR.

52m agoHN ↗

The coding side of this isn't even the problem - that a broken change like this made it to production is an operational failure.

Why didn't testing catch this? Why was there no canary? How come alarms didn't wake up an on call as soon as the call-volume on the backend dropped? Why was this update rolled out to every customer at once, instead of gradually?

50m agoHN ↗

I think verification is still a grey area in the agentic software dev. QA and ppl testing it often resort to coding agents for the QA work, and we all know how good agents are at convincing themselves.

27m agoHN ↗

The solution is testing it yourself, not more AI

39m agoHN ↗

Why pay for and bother with all of that when you can outsource it to your users?

Users who will forget about it, and due to inertia stay on your platform.

23m agoHN ↗

No matter how many times this is said, the reality is that it is not true: no one will get blamed if the AI can be blamed.

5m agoHN ↗

Wrong. They will be totally blamed. And the pushback will be that management forced me to use AI and go fast. Then, management will be the one NOT being blamed for this.

13m agoHN ↗

And in many companies, if they move at a responsible speed (rather than the speed the AI vendors promise, if you let their tools work in yolo mode), that person will get replaced by someone who will just yolo it

1h agoHN ↗

At least Google engineers can invert a binary tree

1h agoHN ↗

Lol, but they can't build BREW ;)

46m agoHN ↗

Yeah, and pinning versions doesn't save you when the config comes from their server.

30m agoHN ↗

Ironic. They could save others from crashes, but not themselves.

14m agoHN ↗

A friendly piece of vocabulary assistance: it's "this morning" ("today morning" is not correct English)