frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Railway knows better than you

https://anukari.com/blog/devlog/railway-knows-better-than-you
3•humbledrone•1h ago

Comments

half0wl•53m ago
I appreciate this blogpost. I'm the one at Railway responsible for this decision, so I wanted to share some context from our side.

First off, sorry you got nailed by this. I genuinely empathize because _we_ got nailed too - the Railway.com frontend is hosted on Railway, and we had references to these vuln versions buried in old packages that weren't used in live code. We couldn't deploy for a bit until we sorted it out. It sucked.

That said, I believe this was the right call for a few reasons:

1. We have to think about our entire userbase. Our DX makes deploying easy, which attracts a lot of non-technical folks such as PMs, vibe cobers, newbies, etc. A significant chunk of them would either have no idea this was happening, no idea what an RCE even is, or no clue how to fix it.

2. We're trying to break the "I'll fix it later cycle" because that mindset is how security debt piles up. Yes, it's a heavy-handed approach. It shifts the action item left in the SDLC by blocking vuln deploys outright. We _could_ just alert people, and we did, but we've learned the hard way that people don't read emails. This was the only intervention that actually worked. Other platforms like Vercel also took the same approach.

3. This disproportionately impacted users who weren't using Next.js. We had to scramble when attackers leveraging this exploit started causing degradation across <10% of our fleet [0].

Your feedback on container and resource isolation is valid; there's stuff we could do better, and we're working on it. As a platform, it's a hard dance between "you got pwn'd for ignoring shit" and "why didn't you protect us from this?"

We made this call to protect the majority, and I recognize it's not going to make everyone happy. Despite this, I would still have made the call. I wished the majority of our userbase knew better than us, but the reality is they don't. My only regret is not making this call earlier when we were first notified. The sad thing here is people like you who _do_ know better than us doesn't have an escape hatch out of this - and I would argue that this isn't an escape hatch we should be providing.

(And for the record, we aren't actively killing live running workloads on vuln versions unless our scanner picks up that they're compromised using heuristics we've developed for known cryptominers, etc.)

[0] https://blog.railway.com/p/incident-report-december-16-2025

edit: typos and minor phrasing tweaks

justjake•38m ago
Jake from Railway here

> And my hosting provider is saying, "you are not allowed to push out your urgent fix, because we see that your app contains a far less urgent problem." There is no button that says "I understand, proceed anyway." Railway knows best.

We rolled this out quickly because of the React/NextJS CVE. I think this is actually a really good suggestion and we can look into it! Thank you for the thoughtful blogpost, and I'm sorry we let you down. We will work hard to re-earn your trust.

Is It a Joke?

https://novalis.org/blog/2025-11-06-is-it-a-joke.html
1•luu•1m ago•0 comments

T5Gemma 2: The next generation of encoder-decoder models

https://blog.google/technology/developers/t5gemma-2/
1•milomg•1m ago•0 comments

Move Expressions (Part of Ergonomic RC for Rust)

https://smallcultfollowing.com/babysteps/blog/2025/11/21/move-expressions/
1•stmw•1m ago•0 comments

Zero Inflation

https://thetontineengine.substack.com/p/make-money-hard-again
1•rwmj•2m ago•0 comments

2026 Demo Day Dates

https://www.ycombinator.com/blog/2026-demo-days/
1•todsacerdoti•3m ago•0 comments

$1,500 robot cooks dinner while I work

https://www.theverge.com/tech/840599/posha-robot-chef-review
1•bookofjoe•4m ago•1 comments

'Mars camp': The extreme adventure that wants to turn tourists into astronauts

https://www.cnn.com/2025/10/23/travel/mongolias-mars-camp-tourist-astronauts-hnk-spc
1•breve•4m ago•0 comments

Our Series B: $330M raised at $6.6B valuation

https://age-of-the-builder.lovable.app/
1•taubek•5m ago•0 comments

How do you find early users for an MVP dev tool?

1•yashwantphogat•6m ago•0 comments

President Orders Cannabis Rules Relaxed, Easing Research

https://www.nytimes.com/live/2025/12/18/us/trump-news
2•thelastgallon•7m ago•1 comments

How to hack discord, vercel and more with one easy trick

https://kibty.town/blog/mintlify/
1•todsacerdoti•7m ago•0 comments

Show HN: Narrativee – Make sense of your data in minutes

https://narrativee.com
2•safoan_eth•9m ago•0 comments

Ask HN: How would you monetize an AI book-writing app?

1•eibrahim•11m ago•1 comments

Study suggests recent tundra fires 'exceed anything in past 3k years

https://phys.org/news/2025-12-tundra-exceed-years.html
1•bikenaga•11m ago•1 comments

Advancements in Agent OS and NatLangChain Ecosystems

https://github.com/kase1111-hash/NatLangChain
1•Kase1111•12m ago•0 comments

Elon Musk's SpaceX bought tens of millions worth of Cybertrucks Tesla can't sell

https://electrek.co/2025/12/18/elon-musks-spacex-bought-tens-of-millions-worth-of-cybertrucks-tes...
7•breve•13m ago•0 comments

ASCII Yin Yang

https://count-quota-18418512.figma.site/
1•matonias•14m ago•1 comments

Show HN: Jules AI GitHub Actions

https://github.com/google-labs-code/jules-action
3•suyashkumar•15m ago•0 comments

Agent Skills open standard

https://agentskills.io/home
1•CharlesW•15m ago•0 comments

There are no shortcuts to affordability

https://stayathomemacro.substack.com/p/there-are-no-shortcuts-to-affordability
1•m-hodges•16m ago•1 comments

Ask HN: What important developments happened in AI/LLMs in 2025?

1•flreln•16m ago•2 comments

Building a Reusable Form Component Library with TanStack Form

https://matthuggins.com/blog/posts/building-a-reusable-form-component-library-with-tanstack-form
1•matthuggins•17m ago•0 comments

We let AI run our office vending machine. It lost hundreds of dollars

https://www.msn.com/en-us/money/other/we-let-ai-run-our-office-vending-machine-it-lost-hundreds-o...
2•airhangerf15•17m ago•0 comments

Xata: Instant branches of your Postgres with anonymized production data

https://xata.io
1•gk1•17m ago•0 comments

Bias gives 'swing state' voters more influence over US trade policy

https://phys.org/news/2025-12-hidden-bias-state-voters-policy.html
3•bikenaga•18m ago•2 comments

One weird trick to manage engineering crises; stakeholders love it

https://www.brethorsting.com/blog/2025/12/one-weird-trick-to-manage-engineering-crises;-stakehold...
1•aaronbrethorst•20m ago•0 comments

Jan Koum (WhatsApp cofounder) tops AIPAC donor list

https://www.trackaipac.com/donors
1•KoftaBob•22m ago•0 comments

They Get Wheeled on Flights and Miraculously Walk Off. Praise ‘Jetway Jesus.

https://www.wsj.com/lifestyle/travel/jetway-jesus-wheelchair-passengers-miracle-flights-0eaccfb3
4•fortran77•22m ago•1 comments

Claude in Chrome

https://claude.com/chrome
1•irrationalfab•23m ago•1 comments

Show HN: Social Media Post Quality Checker

https://socialrails.com/free-tools/social-media-post-quality-check
1•henk2•23m ago•0 comments