Hacker Newsnew | past | comments | ask | show | jobs | submit | MattIPv4's commentslogin

Looks like MLH + DEV have taken over Hacktoberfest, and are trying something new this year: pushing AI development skills and local gatherings, rather than counting how many PRs folks open.


Just ran into a bunch of my E2Es failing on innocuous POST requests. Really interested to know how Cloudflare managed to outright break POST requests going through them.


I can unfortunately report that these dots have not helped me in cars or trains; anything more than a few seconds looking at a screen during a journey will ensure I feel awful until I have an opportunity to sit or lie still for quite a while after. To be fair, even facing backwards on a train usually makes me sick rather rapidly.


Related: https://news.ycombinator.com/item?id=47824426

https://x.com/theo/status/2045862972342313374

> I have reason to believe this is credible.

https://x.com/theo/status/2045870216555499636

> Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution

https://x.com/theo/status/2045871215705747965

> Everything I know about this hack suggests it could happen to any host

https://x.com/DiffeKey/status/2045813085408051670

> Vercel has reportedly been breached by ShinyHunters.


Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.


He’s a tech influencer, probably getting quoted here because he has the biggest reach of people covering this so far.


He’s a streamer who talks about tech. Previously had a sponsorship relationship with Vercel so is theoretically more well connected than average on the topic. He’s also very divisive because he does a lot of ragebait, grievance reporting, and contrarian takes but famously has blind spots for a few companies and technologies that he’s favored in past videos or been sponsored by. I have friends who watch a lot of his videos but I’ve never been able to get into it.


Theo Browne is a reasonably well known YouTuber & YC founder.

https://t3.gg/


He is a paid Vercel shill (literally, he does sponsored content for them on his YouTube channel)



Not in a few years.


YT tech vlogger


> Ones NOT marked as sensitive should be rolled out of precaution

if it's not marked as sensitive (because it is not sensitive) there is no reason to roll them. if you must roll a insensitive env var it should've been sensitive in the first place, no?


There's a difference between sensitive, private and public. If public (i.e. NEXT_PUBLIC_) then yeah likely not a reason to roll. Private keys that aren't explicitly sensitive probably are still sensitive. It doesn't seem to be the default to have things "sensitive" and I can't tell if that's a new classification or has always been there.

I can imagine the reason why an env variable would be sensitive, but need to be re-read at some point. But overwhelmingly it makes sense for the default to be set, and never access again (i.e. Fly env values, GCP secret manager etc)




Hitting 500s when trying to push branches and create PRs.


Related: A better streams API is possible for JavaScript: https://news.ycombinator.com/item?id=47180569


Are y'all aware your agent's name clashes with an established and rather popular streaming bot/tool, https://fossabot.com ?


That would explain why I tried to get vulnerability notifications and instead all my code was streamed to Twitch.


Spitballing some alt names

Fossadep

Fossacheck

Fossasafe


Fossamatta

Fossahappenin

Fossagoinon


Again... Unicorns when trying to view files or PRs, errors trying to leave comments or review things if they do load.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: