logoalt Hacker News

yoaviramtoday at 5:33 AM1 replyview on HN

I believe this is inaccurate. Vercel env vars are all encrypted at rest (on their side). The 'sensitive' checkbox means you can't retrieve the value once it's set, which would have saved your ass in this case. Also, annoying to read an article like this without a single link to source material.


Replies

trick-or-treattoday at 5:45 AM

I think it's clear that some customers env vars got exposed, so that can only mean unencrypted, right?

show 1 reply