logoalt Hacker News

jesse_dot_idtoday at 5:02 AM2 repliesview on HN

> How many developers do you think knew that checkbox existed? How many assumed their database credentials and API keys were encrypted by default?

If I don't see asterisks, I'm not hitting save on the field with a secret in it. Maybe they were setting them programmatically? They should definitely still be looking to pass some kind of a secret flag, though. This is a weird problem for a company like Vercel to have.


Replies

apgwoztoday at 5:09 AM

You pretty much have to assume someone is going to put sensitive data in an input like this. Encryption by default is the only sensible choice.

show 1 reply
SOLAR_FIELDStoday at 5:37 AM

Do you ask a bridge engineer if they forgot to reinforce the supports when they built the bridge? Even when I didn't know about security this was a table stakes thing. People saving sensitive things in plaintext are upset that their poor practices came back to bite them. Now, at the risk of sounding like I'm victim blaming here, Vercel is also totally bearing some responsibility for this insanity. But come on. FAFO and all that.