frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A Roblox cheat and one AI tool brought down Vercel's platform

https://webmatrices.com/post/how-a-roblox-cheat-and-one-ai-tool-brought-down-vercel-s-entire-platform
68•bishwasbh•1h ago

Comments

EdwardDiego•1h ago
A frigging Roblox cheat...

And I thought it was bad when my son got compromised by a Roblox cheat, but they only they grabbed his Gamepass cookies and bought 4 Minecraft licenses, which MS quickly refunded...

jesse_dot_id•1h ago
> How many developers do you think knew that checkbox existed? How many assumed their database credentials and API keys were encrypted by default?

If I don't see asterisks, I'm not hitting save on the field with a secret in it. Maybe they were setting them programmatically? They should definitely still be looking to pass some kind of a secret flag, though. This is a weird problem for a company like Vercel to have.

apgwoz•56m ago
You pretty much have to assume someone is going to put sensitive data in an input like this. Encryption by default is the only sensible choice.
SOLAR_FIELDS•28m ago
Do you ask a bridge engineer if they forgot to reinforce the supports when they built the bridge? Even when I didn't know about security this was a table stakes thing. People saving sensitive things in plaintext are upset that their poor practices came back to bite them. Now, at the risk of sounding like I'm victim blaming here, Vercel is also totally bearing some responsibility for this insanity. But come on. FAFO and all that.
ethin•52m ago
This looks really really AI-generated even if the author did try to hide it by making some grammar elements improper. Idk if that diminishes it's accuracy though.
progbits•35m ago
I don't know why you are downvoted. The article is AI blogspam, it doesn't have any more factual information than eg https://www.darkreading.com/application-security/vercel-empl... and is full of empty LLMisms. It's depressing people are willing to read this.
mchl-mumo•28m ago
I didn't notice till I saw this comment and now I'm also confident it's significantly AI written.
progval•27m ago
Because a comment that just says it's AI generated provides no value to the readers. They could at least provide an alternative link like you did.
varun_ch•46m ago
Context.ai seems like it was the SPOF. By definition it has a lot of your data, and they didn’t secure it properly.
trick-or-treat•17m ago
Clearly, Vercel should not have been compromised by this. I don't know who Context.ai is but I do know Vercel and I expected better from them. I also think we can expect to see a lot more stories like this.
R41•45m ago
good article, these AI products are crazy supply chain risks.
mudkipdev•39m ago
I'm getting a "failed to verify your browser" error on this article
NitpickLawyer•15m ago
And, ironically, it's hosted on vercel :D
ChrisArchitect•38m ago
Related:

Vercel April 2026 security incident

https://news.ycombinator.com/item?id=47824463

ryanisnan•36m ago
Convenience is our Achilles heel, as a society.

We'll keep dangerous devices like the SuperBox in our homes, if it helps us get access to free movies and tv.

We'll use single-use plastics, even if we know they're bad for the environment, because they're just so damn easy.

We'll let AI run that thing for us, because it's just too easy.

A whole generation has grown up without knowing what it was like to infect your computer with AIDS trying to download an MP3, and it shows. That caution will come back, just at a terrible cost.

trick-or-treat•15m ago
When life gives you AIDS, make lemonAIDS!
yoaviram•32m ago
I believe this is inaccurate. Vercel env vars are all encrypted at rest (on their side). The 'sensitive' checkbox means you can't retrieve the value once it's set, which would have saved your ass in this case. Also, annoying to read an article like this without a single link to source material.
trick-or-treat•20m ago
I think it's clear that some customers env vars got exposed, so that can only mean unencrypted, right?
TheDong•16m ago
They said "encrypted at rest", which they almost certainly are.

If you spin up an EC2 instance with an ftp server and check the "Encrypt my EBS volume", all those files are 'encrypted at rest', but if your ftp password is 'admin/admin', your files will be exposed in plaintext quite quickly.

Vercel's backend is of course able to decrypt them too (or else it couldn't run your app for you), and so the attacker was able to view them, and presumably some other control on the backend made it so the sensitive ones can end up in your app, but can't be seen in whatever employee-only interface the attacker was viewing.

trick-or-treat•12m ago
Hmm, that's confusing. So they're eventually encrypted but plain-text at some point? Doesn't sound good TBH.
magackame•6m ago
It seems only encrypt and throw away the key would be the acceptable strategy
kstrauser•26m ago
I think this is wrong about what “sensitive” means here. AFAIK, all Vercel env cars are encrypted. The sensitive checkbox means that a develop looking at the env var can’t see what value is stored there. It’s a write-only value. Only the app can see it, via an env var (which obviously can’t be encrypted in such a way that the app can’t see it, otherwise it’d be worthless). If you don’t check that box, you can view the value in the project UI. That’s reasonable for most config values. Imagine “DEFAULT_TIME_ZONE” or such. There’s nothing gained from hiding it, and it’d be a pain in the ass come troubleshooting time.

So sensitive doesn’t mean encrypted. It means the UI doesn’t show the dev what value’s stored there after they’ve updated it. Not sensitive means it’s still visible. And again, I presume this is only a UI thing, and both kinds are stored encrypted in the backend.

I don’t work for Vercel, but I’ve use them a bit. I’m sure there are valid reasons to dislike them, but this specific bit looks like a strawman.

trick-or-treat•22m ago
According to the email I got from Vercel it was a limited subset of customers and I'm not one:

Initially, we identified a limited subset of customers whose Vercel credentials were compromised. We reached out to that subset and recommended that they rotate their credentials immediately.

At this time, we do not have reason to believe that your Vercel credentials or personal data have been compromised.

doctorpangloss•11m ago
This article is LLM authored and full of hallucinations. "Let that sink in for a second."

Reduce hiring overhead with real work trials

1•saurav18s•2m ago•0 comments

Google Cloud in the list of 4 EU sovereign cloud providers

https://www.theregister.com/2026/04/20/europe_picks_4_sovereign_cloud/
1•kouzant•2m ago•0 comments

Amazon 'strong-armed' Levi's, Hanes to hike prices on rival sites, DA says

https://www.cnbc.com/2026/04/20/california-da-amazon-price-fixing-walmart-target.html
1•1vuio0pswjnm7•4m ago•0 comments

Canada has banned employers from ghosting job candidates

https://www.positive.news/society/canada-has-banned-employers-from-ghosting-job-candidates/
3•jethronethro•4m ago•0 comments

Types and Neural Networks

https://www.brunogavranovic.com/posts/2026-04-20-types-and-neural-networks.html
1•bgavran•6m ago•0 comments

With Orban Out, the Pianist András Schiff Plans a Return to Hungary

https://www.nytimes.com/2026/04/20/arts/music/andras-schiff-piano-viktor-orban-hungary.html
1•mykowebhn•10m ago•0 comments

In major policy shift, Japan scraps limits on lethal arms exports

https://www.japantimes.co.jp/news/2026/04/21/japan/politics/japan-lethal-weapons-export-rules-eased/
1•geox•11m ago•0 comments

The Hero's Journey Is Burning the Planet

https://abiawomosu.substack.com/p/the-heros-journey-is-burning-the
1•rcy•11m ago•0 comments

At Long Last, InfoWars Is Ours

https://theonion.info/
1•throwaway81523•15m ago•0 comments

Bcachefs 1.38.0 Released

https://evilpiepirate.org/git/bcachefs-tools.git/tree/Changelog.mdwn
1•d12bb•15m ago•0 comments

What skills are future proof in an AI driven job market?

3•sunny678•16m ago•3 comments

ClearTask

https://0d07b74677d946ca9e.v2.appdeploy.ai/
1•Girtino•17m ago•1 comments

The Propulsion Papers

https://uniliterate.com/2026/03/part-iii-forensic-fake-ai-citations/
1•jruohonen•19m ago•1 comments

Flipbook – one-click file sharing for visual media scrubbing

https://browser-session-it94u.pages.dev/
1•keepamovin•28m ago•2 comments

Using a Bitcoin Microstructure Model to Predict Epileptic Seizures

https://zenodo.org/records/19669062
1•juhopaajanen•29m ago•0 comments

The Vercel Breach Needed Malware. The Next One Needs a Bad Readme

https://grith.ai/blog/next-vercel-breach-ai-coding-agent
1•edf13•33m ago•3 comments

Claude Cowork now has Live Artifacts

https://support.claude.com/en/articles/9487310-what-are-artifacts-and-how-do-i-use-them
1•manishfp•35m ago•1 comments

Following America's Artemis-2 Moon Mission Through China

https://www.china-in-space.com/p/following-americas-artemis-2-moon
1•JPLeRouzic•35m ago•0 comments

GitHub Copilot Pro+ not allowing Claude Opus 4.6

https://github.com/microsoft/vscode/issues/311590
2•vikrantrathore•37m ago•1 comments

The Toaster Project(2011) [pdf]

https://www.thomasthwaites.com/folio5/wp-content/uploads/2019/07/Toaster_Project-Thomas_Thwaites-...
1•o4c•38m ago•0 comments

Amazon to invest up to $25B in Anthropic as part of $100B cloud deal

https://www.reuters.com/technology/anthropic-spend-over-100-billion-amazons-cloud-technology-2026...
2•teleforce•38m ago•0 comments

Cocaine pollution gives salmon wanderlust

https://www.science.org/content/article/cocaine-pollution-gives-salmon-wanderlust
2•1659447091•38m ago•0 comments

Most "launch platforms" are built backwards (and it hurts solo founders)

https://buildfeed.co
1•moodiverse•39m ago•1 comments

Show HN: PrivacyScrubber - Local PII redactor for AI (works in Airplane Mode)

https://www.privacyscrubber.com/
1•privacyscrubber•41m ago•0 comments

Lipovive Helps Boost Metabolism and Burn Fat

https://www.morningstar.com/news/accesswire/1138075msn/lipovive-reviews-shocking-2026-report-what...
1•FinnMarden•41m ago•0 comments

Tim Cook Steps Down as CEO of Apple Inc

https://www.apple.com/community-letter-from-tim/
3•Koshima•43m ago•0 comments

Show HN: AI agents deploy apps autonomously (no accounts, no API keys)

https://nodeops.network/createos/docs/MPP/Overview
1•alex_creates•44m ago•0 comments

I analysed 17 years of fast food and coffee spending using OpenAI Codex

https://chrisflemming.com/blog/20260421-fast-food-coffee-spending-codex/
1•cpf_au•44m ago•0 comments

Trump signs order to accelerate access to psychedelic drug treatments

https://www.reuters.com/world/trump-announces-reforms-accelerate-access-psychedelic-drug-treatmen...
2•XzetaU8•48m ago•0 comments

Mason – A multi agent system in a container using Claude Code

https://github.com/Mason-Teams/mason-teams
1•dpark2026•49m ago•1 comments