frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Incident March 30th, 2026 – Accidental CDN Caching

https://blog.railway.com/p/incident-report-march-30-2026-accidental-cdn-caching
31•cebert•2h ago

Comments

stingraycharles•1h ago
This write up doesn’t make sense. Authenticated users are the ones without a Set-Cookie? Surely the ones with the cookie set are the authenticated ones?

There are dozens of contradictions, like first they say:

“this may have resulted in potentially authenticated data being served to unauthenticated users”

and then just a few sentences later say

“potentially unauthenticated data is served to authenticated users”

which is the opposite. Which one is it?

Am I missing something, or is this article poorly reviewed?

justjake•1h ago
Fixed the typo in that second paragraph and aligned the section on the Set-Cookie stuff. Anything else that can be made more clear?
codechicago277•24m ago
The problem is that these visible errors make us wonder what other errors in the post are less visible. Fixing them doesn’t fix the process that led to them.
slopinthebag•14m ago
I'm pretty sure it's AI.

https://x.com/JustJake/status/2007730898192744751

I wouldn't be surprised if most of Railway's infra is running on Claude at this point.

DrewADesign•9m ago
It appears that your company experienced an incident during which a blog entry was made available in which readers became informed about certain information about a server condition that resulted in certain users receiving a barrage of indirect clauses etc. etc. etc.

Be more direct. Be concise. This blog post sounds like a cagey customer service CYA response. It defeats the purpose of publishing a blog post showing that you’re mature, aware, accountable, and transparent.

sublinear•1h ago
I'm curious if having unique URLs per user session would mitigate this.

I think that's already best practice in most API designs anyway?

sebmellen•55m ago
Almost three years ago now, Railway poached one of our smartest engineers. They were smart to do so. I have a lot of respect for the Railway team and I’m impressed with their execution.

I think this is their first major security incident. Good that they are transparent about it.

If possible (@justjake) it would be helpful to understand if there was a QA/test process before the release was pushed. I presume there was, so the question is why this was not caught. Was this just an untested part of the codebase?

varun_chopra•46m ago
The status page [1] has the actual root cause (enabling "Surrogate Keys" silently bypassed their CDN-off logic). The blog post doesn't. That's backwards.

"0.05% of domains" is a vanity metric -- what matters is how many requests were mis-served cross-user. "Cache-Control was respected where provided" is technically true but misleading when most apps don't set it because CDN was off. The status page is more honest here too: they confirmed content without cache-control was cached.

They call it a "trust boundary violation" in the last line but the rest of the post reads like a press release. No accounting of what data was actually exposed.

[1] https://status.railway.com/incident/X0Q39H56

Axios Compromised on NPM – Malicious Versions Drop Remote Access Trojan

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-t...
73•mtud•57m ago•16 comments

Universal Claude.md – cut Claude output tokens by 63%

https://github.com/drona23/claude-token-efficient
154•killme2008•2h ago•65 comments

Artemis II is not safe to fly

https://idlewords.com/2026/03/artemis_ii_is_not_safe_to_fly.htm
43•idlewords•1h ago•15 comments

Fedware: Government apps that spy harder than the apps they ban

https://www.sambent.com/the-white-house-app-has-huawei-spyware-and-an-ice-tip-line/
474•speckx•9h ago•149 comments

Do your own writing

https://alexhwoods.com/dont-let-ai-write-for-you/
412•karimf•15h ago•147 comments

Android Developer Verification

https://android-developers.googleblog.com/2026/03/android-developer-verification-rolling-out-to-a...
172•ingve•5h ago•158 comments

Incident March 30th, 2026 – Accidental CDN Caching

https://blog.railway.com/p/incident-report-march-30-2026-accidental-cdn-caching
31•cebert•2h ago•8 comments

Turning a MacBook into a touchscreen with $1 of hardware (2018)

https://anishathalye.com/macbook-touchscreen/
231•HughParry•8h ago•101 comments

How to turn anything into a router

https://nbailey.ca/post/router/
620•yabones•14h ago•215 comments

Learn Claude Code by doing, not reading

https://claude.nagdy.me/
191•taubek•7h ago•93 comments

Clojure: The Documentary, official trailer [video]

https://www.youtube.com/watch?v=JJEyffSdBsk
56•fogus•4d ago•2 comments

Unit: A self-replicating Forth mesh agent running in a browser tab

https://davidcanhelp.github.io/unit/
10•DavidCanHelp•4d ago•1 comments

Show HN: I turned a sketch into a 3D-print pegboard for my kid with an AI agent

https://github.com/virpo/pegboard
14•virpo•4h ago•2 comments

Agents of Chaos

https://agentsofchaos.baulab.info/report.html
84•luu•3d ago•9 comments

Bird brains (2023)

https://www.dhanishsemar.com/writing/bird-brains
302•DiffTheEnder•14h ago•192 comments

OpenGridWorks: The Electricity Infrasctructure, Mapped

https://www.opengridworks.com
65•jonbraun•6h ago•4 comments

Cherri – programming language that compiles to an Apple Shortuct

https://github.com/electrikmilk/cherri
275•mihau•3d ago•54 comments

Researchers find 3,500-year-old loom that reveals textile revolution

https://web.ua.es/en/actualidad-universitaria/2026/marzo2026/23-31/ua-researchers-find-3-500-year...
87•geox•3d ago•8 comments

Why I'm betting on ATProto (and why you should, too)

https://brittanyellich.com/atproto/
95•speckx•8h ago•76 comments

CodingFont: A game to help you pick a coding font

https://www.codingfont.com/
345•nvahalik•12h ago•187 comments

Seeing Like a Spreadsheet

https://davidoks.blog/p/how-the-spreadsheet-reshaped-america
85•paulpauper•2d ago•31 comments

Roulette Computers: Hidden Devices That Predict Spins

https://www.roulette-computers.com/
79•o4c•2d ago•29 comments

William Blake, Remote by the Sea

https://www.laphamsquarterly.org/roundtable/william-blake-remote-sea
65•occurrence•8h ago•4 comments

I am definitely missing the pre-AI writing era

https://www.lesswrong.com/posts/BJ4pnropWdnzzgeJc/i-am-definitely-missing-the-pre-ai-writing-era
292•joozio•20h ago•214 comments

Show HN: Coasts – Containerized Hosts for Agents

https://github.com/coast-guard/coasts
67•jsunderland323•12h ago•28 comments

Recover Apple Keychain

https://arkoinad.com/posts/apple_keychain_recovery.html
66•speckx•10h ago•23 comments

In math, rigor is vital, but are digitized proofs taking it too far?

https://www.quantamagazine.org/in-math-rigor-is-vital-but-are-digitized-proofs-taking-it-too-far-...
109•isaacfrond•4d ago•99 comments

Principles and Gear

https://arun.is/blog/on-running/
13•surprisetalk•4d ago•2 comments

Build123d: A Python CAD programming library

https://github.com/gumyr/build123d
128•Ivoah•1d ago•49 comments

A sea of sparks: Seeing radioactivity

https://maurycyz.com/projects/spinthariscope/
57•maurycyz•9h ago•19 comments