logoalt Hacker News

MattIPv4yesterday at 2:39 PM2 repliesview on HN

Related: https://news.ycombinator.com/item?id=47824426

https://x.com/theo/status/2045862972342313374

> I have reason to believe this is credible.

https://x.com/theo/status/2045870216555499636

> Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution

https://x.com/theo/status/2045871215705747965

> Everything I know about this hack suggests it could happen to any host

https://x.com/DiffeKey/status/2045813085408051670

> Vercel has reportedly been breached by ShinyHunters.


Replies

tom1337yesterday at 7:31 PM

> Ones NOT marked as sensitive should be rolled out of precaution

if it's not marked as sensitive (because it is not sensitive) there is no reason to roll them. if you must roll a insensitive env var it should've been sensitive in the first place, no?

show 1 reply
otterleyyesterday at 3:48 PM

Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.

show 6 replies