Nayan

1.2K posts

Nayan banner
Nayan

Nayan

@0xNayan

Building Userplane | Loom for Customer Support

Katılım Mart 2021
679 Takip Edilen291 Takipçiler
Sabitlenmiş Tweet
Nayan
Nayan@0xNayan·
when you finish rebuilding @karpathy nanochat only to remember your actual job for the foreseeable future is still gonna be building agents that are just OpenAI calls in a for loop
English
40
166
3.9K
329K
Nayan
Nayan@0xNayan·
me irl lately
English
0
0
1
21
Nayan
Nayan@0xNayan·
just 1 more SKILL.md bro it'll fix everything bro trust me bro it'll fix everything bro trust me bro
English
0
0
0
20
Nayan
Nayan@0xNayan·
with low cortisol comes great aura
English
0
0
0
16
Nayan
Nayan@0xNayan·
the kind of baddie you meet at your workplace when you’re in your notice period
English
0
0
0
55
Nayan
Nayan@0xNayan·
me and who?
English
0
0
0
20
Nayan
Nayan@0xNayan·
that one mf after breaking up with a girl he never dated
English
0
0
1
28
Nayan
Nayan@0xNayan·
when a 2/10 work wifey says her plant died
English
0
0
1
28
Nayan
Nayan@0xNayan·
meanwhile at @cloudflare
Guillermo Rauch@rauchg

Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.

English
0
0
1
70
Nayan
Nayan@0xNayan·
“claude, listen make no mistakes. you’re a senior frontend engineer”
English
1
0
2
57
Nayan
Nayan@0xNayan·
"yeah so I have this startup which I'm building in stealth"
English
0
0
0
31
Nayan
Nayan@0xNayan·
your indie hacker friend, when asked if he talked to customers before building the product :
English
1
0
5
76
Nayan
Nayan@0xNayan·
me when claude code tells me the feature will take 3-4 weeks
English
1
0
3
75
Hahnbee Lee
Hahnbee Lee@hahnbeelee·
@n0w00j there's prolly some word play with series D too 🤣
English
2
0
5
297
Hahnbee Lee
Hahnbee Lee@hahnbeelee·
single till series b is true i guess
Hahnbee Lee tweet media
English
48
8
946
60.4K
Nayan
Nayan@0xNayan·
it's time to build fellas it's time to build
English
0
0
2
54
Nayan
Nayan@0xNayan·
indie hackers getting their 1st $13/mo customer (after quitting their $500k/yr job) :
English
0
0
1
57
Nayan
Nayan@0xNayan·
so...did you talk to customers before building the product?
Nayan tweet media
English
2
0
4
57
Nayan
Nayan@0xNayan·
fellas maybe there's more to life than anime
Nayan tweet media
English
0
0
1
34
Nayan
Nayan@0xNayan·
leaked video of the Bangalore YC Startup School
English
0
0
2
220