Meta is no different. I know a company that had their OAuth app on Meta rendered completely unusable just because one of their employees (a dev) had their personal Facebook account banned by Meta for no reason. They tried to escalate it multiple times but got nowhere, lol. Meta is even worse because accounts need to be 'personal'; if you have a Business Manager, the users added to it are all tied to their personal Meta/Facebook accounts. This is ludicrous.
Yeah, people loose their business because a kid is logged in on their iPad, gets their google account suspended, and google knows it's the same household as the parent, and everything gets shut down
Are you honestly saying that a kid should not use their parent's email address as a recovery option? Seems like that would be the natural way to do it.
I don’t know about you, but I have a family account that we use as an email recovery for kids.
Adults have multiple emails so they won’t have to share it.
If something takes out the family email account, that’s fine. The only thing going there regularly are school notices, contractor receipts and recovery emails.
Point is that if one account gets suspended, all your accounts might. Your kids', the family account, your separate one that you use for gcp billing etc
Meta and Google B2B are both horrible. Their ad account bans are constant, and they have no real escalation process to get help. These companies are monopolies that should treat businesses more seriously, especially in these situations.
Crazy considering this was their primary argument against the App Store's revenue share model. Not that they're wrong, but you'd think they would at least be consistent.
A huge number of small businesses have no Internet presence beyond their Facebook and Insta pages, so … yes they are extremely relevant to a discussion about the risk to small business of flaky hyperscalers.
More businesses need to hear this message. Google has proven time and time again they cannot be trusted as a service provider, exactly because of this problem.
Never could. Google might block your entire company because one of your workers did something nasty on their personal account, and their ban hammer is mighty and blocks all related accounts to the Nth degree
I've been wondering if I should be interrogating my friends before allowing them access to my wifi. "Have you or any of your family members ever been banned by Google?"
There is a history going back many years of Google suspending or terminating accounts with no explanation, often having to backtrack after users published their frustration and the incident went viral.
Google has always acted as if they have no obligations whatsoever to their paying customers.
They have not explained WHY their account was suspended. That's the most important part, imo. Cloud Providers don't suspend entire accounts for no reason.
> "Cloud Providers don't suspend entire accounts for no reason."
Maybe I'm getting old but here[1] is a HN comment from 17 years ago complaining about Google banning accounts "by mistake" and having no recourse but to post on HN and hope Matt Cutts sees it and helps, and saying "there are literally 1000s of such stories for many years all over the blogoshphere and forums" which is something I remember from HN of years ago.
In May 2024, Google Cloud Platform (GCP) accidentally deleted the private cloud account and all backups belonging to UniSuper, an Australian pension fund managing over $125 billion.
They are a pension fund; they literally had/have US$125 billion dollars under management. What exactly is being stretched here? I can't for the life of me think of something that qualifies more for being a 125b company than actually having 125b in assets.
Having assets under management doesn't mean you have that money. You don't own it, you are just taking care of it for somebody. When describing a company as an $X billion company, conventionally this is referring to the market cap. You could use it to describe other things they possess if you wanted to, but assets they manage will never be something they possess.
Language is a communication tool. If you misuse language you will be badly understood. The solution is to use the correct word for what you mean, not to accuse others of sophistry.
Companies are described by revenue. UniSuper made $110 million recently. It deceptive to use the assets managed as the size since it makes it look like a much larger company. NVIDIA has revenue of $130 billion. $125 billion revenue would make it the largest company in Australia by a good amount.
That's fair, but if I'm a fund that can literally write a check the size of my endowment, why is that not a demonstration of my value? That's not finance 101, but you get to it later on.
They have 125b they can literally write a check against and allocate any way they want as long as it delivers an adequate return and doesn't piss off the shareholders. Other than sophistry, what's the difference?
> They have 125b they can literally write a check against and allocate any way they want as long as it delivers an adequate return and doesn't piss off the shareholders.
No they don't. The pension regulator sets very restrictive controls on what they can do with that 125b, because it's neither the company's nor the shareholders' money.
> Google Cloud placed Railway’s production account into a suspended status incorrectly, as part of an automated action. This action extended to many accounts within Google Cloud. As this was a platform-wide action, there was no proactive outreach to individual customers prior to the restriction.
If it were something out of Railways hands, I think they would say something like "We have not yet identified the reason for the suspension, and are awaiting a response from Google".
At any company doing Enterprise work, you don't cut off someone for non payment without Account Manager doing multiple phone calls to whoever you have contact information for, emailing everyone listed on the account and whoever opened a support ticket and maybe even putting a banner in the panel with "ACCOUNT OVERDUE, CALL US TO SORT IT OUT!"
Generally it takes 30 days past due and complete no contact for anyone before suspension.
That was normal US B2B behavior until recently. A supplier that cut off their customers for no good reason would lose their reputation in the industry and have real problems selling.
Then we got down to a very small number of major suppliers in some areas. Many have moats that deter switching. This gives the big suppliers too much power.
A century ago, this happened with railroads. Which is why railroads were forced to become common carriers. They're required to transport goods for anybody who can pay. Read up on antitrust activity of a century ago. We've been here before.
Cloud Providers don't suspend entire accounts for no reason.
Oh...my. Just starting out in the industry, are we? Those of us who have been here for a while know reality is very different than newbie hopes and dreams. Once you've been burned for the n+1 time, that optimism will fade.
In practice, Google has earned the way my priors are ready to believe it's 100% their fault with mighty and sustained effort. Or lack thereof, depending on your point of view.
> Google Cloud placed Railway’s production account into a suspended status incorrectly, as part of an automated action. This action extended to many accounts within Google Cloud. As this was a platform-wide action, there was no proactive outreach to individual customers prior to the restriction.
Railway don't have a great reputation for building scalable systems (effects of vibe coding?). It's worth waiting for Google's response before jumping to conclusions. They can move to Azure/AWS/own datacenter, but there's a good chance this will repeat in a few months.
Sure, if this was one off isolated incident people would have agreed with you. But it's not. Even Google personal accounts have been used to ban their other ones including ones spending thousands of dollars on ads or GCP or any other paid google service, which is ridiculous.
Their reputation is fine, and their uptake is due in part to their handling of scaling.
If you're picking them instead of the underlying cloud provider, but you want all the knows and dials the underlying provider has, you've made the wrong choice.
I understand this opinion, because their API keys / OAuth tokens had no permissions structure, so a user of the Railway MCP had their infrastructure destroyed by an overzealous LLM agent. However, this is orthogonal to their infrastructure capabilities.
Been a passive reader here at HN for too long, finally registered today. Instead of viewing this incident objectively, you choose to insult me (?).
I know multiple startup founders personally (2 of them are in the current YC batch), and the sheer callousness with which they look at infra, especially from security/scalability/reliability angle is shocking.
I'll personally reserve judgement against GCP (replace with AWS/Azure/OCI/whatever) until we know more.
Then let me be the not day-one account to say Railway is utterly bearing some responsibility here.
"However, in this ring, there was still a hard dependency on workload discoverability being tied to the network control plane API that was hosted on the machines running in Google Cloud."
They've gotta be joking me that they deliberately left something so critical under the control of any other entity than themselves. That demonstrates a lack of critical planning and a lack looking at their configuration from a first-principles approach.
There is always responsibility with Railway, that's given. But also taking into account how many big websites went down when AWS was down, building critical redundancy at such large scale is not cheap, and not many companies do it. Same as security theatre, we have redundancy theatre because they needed to sell the CLOUD.
That's pretty clear. Google can no longer be trusted as a B2B service provider.