Quantcast StorefrontBacktalk » Blog Archive » 1-800-Flowers Site Reported Down For 65 Hours. The Reality, Though, Was Quite Different
advertisement
advertisement

1-800-Flowers Site Reported Down For 65 Hours. The Reality, Though, Was Quite Different

Written by Evan Schuman
October 15th, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

Having long grown comfortable with using uptime monitoring services to check their own site’s ongoing performance, many retailers are toying with using such services to watch for problems with direct rivals. And they have customized E-mail blasts ready to launch at the first sign of trouble.

But an incident this week involving 1-800-Flowers—which the retail chain may have been utterly unaware of—illustrates one of the dangers of using Web monitoring services to track sites other than your own.

One site monitoring company this week reported that the 1-800-Flowers.com E-Commerce site was down for a whopping 65 hours and 26 minutes. The flower company didn’t respond to our inquiries, but a fairly perplexed representative of the monitoring firm did.

“To be honest, this is one of those rare cases where I’m not entirely sure if this is legitimate downtime, that is, downtime that regular human Web site visitors would notice,” he said.

The representative said his system’s request was redirected in a loop in the vendor site and was “bounced between two servers indefinitely” until the monitoring software gave up. “What could be happening is that they, for some reason, try to set a cookie on our end and that the server it redirects to depends on that cookie (our system doesn’t allow cookies) and, therefore, when it can’t find a cookie, sends back the request and so on. On the other hand, if that’s the case, I don’t know why it isn’t broken all the time.”

Peter Alguacil, a Web analyst for site monitoring company Pingdom, said site monitors are primarily designed for use by site owners who know their sites inside and out.

“When you monitor your own site, you know all the idiosyncrasies from the backend,” Alguacil said. “If you for some reason are monitoring others’ sites, then you need to be aware that they may have some idiosyncrasies that kick in at some point.”

Alguacil said site monitoring companies rely on software that emulates Web browsers, a practice that usually works fine but can, on rare occasions, report errors real browsers would forgive.


advertisement

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

Kill All The Passwords

This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly. Read more...
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis. Read more...