Sam

167 posts

Sam banner
Sam

Sam

@Guruu75

Building procucts I use.

Paris, France Katılım Eylül 2024
38 Takip Edilen43 Takipçiler
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 Over 700 Ghost CMS sites, including Harvard, Oxford, and Auburn, were compromised through an unauthenticated SQL injection (CVE-2026-26980). Attackers pulled Admin API Keys and turned every site into a ClickFix delivery vector via fake Cloudflare "verify you are human" pages. Patch was out February 19. Most never applied it.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
8
56
452
35.8K
Sam
Sam@Guruu75·
@MennelDev J’ai démarré avec ADA ! 😬 Maintenant je me régale en SvelteKit
Français
0
0
1
66
Mennel 🏛️
Mennel 🏛️@MennelDev·
mon premier langage c'était PHP maintenant j'suis sur react native/expo 90% du temps c'est quoi votre premier vs maintenant ??
Français
30
0
22
7.9K
Sam
Sam@Guruu75·
@bridgemindai I couldn’t even consider letting an AI touching my production environment. I now understand how some of us have their production DB randomly deleted.
English
0
0
0
21
BridgeMind
BridgeMind@bridgemindai·
Claude Code just stopped a DDoS attack on BridgeMind in under 10 minutes. 13 million requests per minute hitting our API. CPU pegged at 94%. Latency spiking to 60 seconds. Production was down. I opened Claude Opus 4.7 in Claude Code and said "fix this now." It identified the attack, scaled ECS from 2 to 8 tasks, tightened WAF rules from 300 to 100 req/IP, blocked the attack vector, and brought CPU down to 15%. Latency dropped from 60 seconds to 1.25 seconds. No DevOps team. No on-call engineer. Just one prompt. This is why I keep coming back to Claude Code.
BridgeMind tweet media
English
91
63
1.3K
103.2K
Cloudflare Developers
Cloudflare Developers@CloudflareDev·
Multiple security vulnerabilities affecting React Server Components and Next.js have been disclosed. We strongly recommend updating your applications immediately. Cloudflare WAF managed rules already mitigate the disclosed denial-of-service vulnerabilities, and we are investigating additional coverage for several other CVEs. developers.cloudflare.com/changelog/post…
English
89
304
1.7K
1M
Sam
Sam@Guruu75·
@0to1guy @melvynx Sure that if you activate rls on Neon or anywhere else, at the end it’s the same thing !
English
0
0
0
30
Melvyn • Builder
Melvyn • Builder@melvynx·
Why you should NOT use Supabase: 1. SDK Trap - not TypeScript by default, type-gen is bad, easy to make mistakes 2. Security with the SDK is terrible - need to set up a lot of things to have something work 3. Vendor lock-in with the Auth, don't have your keys 4. Pricing way more expensive than a $8/month db + better-auth 5. Better alternative for all tools they provide
English
49
6
126
26.7K
Sam
Sam@Guruu75·
@marclou More Laravel and more SvelteKit ! ❤️
Dansk
0
0
0
33
Marc Lou
Marc Lou@marclou·
Founders who build profitable startups use NextJS + TailwindCSS + PostgreSQL n=200
Marc Lou tweet media
English
172
61
1.2K
91.9K
Marc Lou
Marc Lou@marclou·
My friend @jackfriks told me he received a message from someone running a phishing scam on TrustMRR. My security filter marked the message as spam, but I was still curious, so I followed the link. The scammer pretends to be me, claiming to be building a new integration for TrustMRR, and asking for Vercel API keys ☠️ Since the phishing site was hosted on Vercel, I messaged @rauchg & @andrewqu. 6 minutes later, the scammer was blocked on Vercel 😇
Marc Lou tweet mediaMarc Lou tweet media
English
114
11
613
59.6K
Sam
Sam@Guruu75·
@DevBredda @melvynx don't get me wrong. i'm not saying you shouldn't use it. i said you shouldnt rely exclusively on it and you have to understand the security basics
English
1
0
1
30
Sam
Sam@Guruu75·
@DevBredda @melvynx + never trust Claude and agents for security purposes, if you’re not able to handle it by your own knowledge, it’s over
English
1
0
0
47
Sam
Sam@Guruu75·
You’re right. Supabase is not the problem itself. But for most of people (me included), accessing your db with a passphrase and your rbac at backend level is much more natural than having hardly readable rls policy at db level. I like supabase if you don’t want to handle complex backend logic but the issue is that it became the default tool for most of vibecoders who think they are protected because « it works ». Indeed it works, but with one missing rls, your data is absolutely free 😂
English
2
0
1
69
Sam
Sam@Guruu75·
Neon is a real thin Postgres wrapper (if you don’t use their auth) if you want a serverless db. Supabase ecosystem is a real BaaS. The whole Supabase PostgREST and db logic with anon key and RLS is powerful but really dangerous when you don’t really master it. And as most of vibecoders have no clue of it… it becomes a security nightmare in most of products.
English
1
0
1
324
Sam
Sam@Guruu75·
@andi_losing Let’s go man ! Did you have precious experience on app dev ? Keep pushing 💪
English
0
0
0
7
Andi
Andi@andi_losing·
my first iOS app is finally live 🥳 introducing StepKey an app that makes you walk to unlock your apps no steps = no doom scrolling i can’t stop smiling :)
Andi tweet media
English
319
31
1.4K
213.4K
Sam
Sam@Guruu75·
@andi_losing That’s so nice to see your journey Andi ! Wishing you all the best 💪
English
0
0
0
19
Le Dev ULTIME 🍜
Le Dev ULTIME 🍜@ledevultime·
2 millions d'euros ! Je viens d'atteindre les 2M€ avec mon app. J'avais déjà dépassé ce chiffre en USD, mais en EURO ça fait quelque chose. Preuve sur Stripe avec un lien pour mes haters. profile.stripe.com/teachizyfr/cdL…
Le Dev ULTIME 🍜 tweet media
Français
51
7
208
86.2K
Sam
Sam@Guruu75·
@Pauline_Cx @melvynx self host your own Postgres or simply use Neon if you prefer serverless functions and services
English
0
0
0
29
Melvyn • Builder
Melvyn • Builder@melvynx·
It's been 4 years that I advise everyone to not use this Supabase ⚠️ → expensive + limiting (2 free projects then $20 / project) → auth is meh → vibe coding has 80% of creating security issues with their SDK I just don't count the number of junior devs building with Supabase making security vulnerabilities that enable anyone to get all user data ☠️
Sara Dietschy 🍑y@saradietschy

Maybe it's my YouTube search being messed up (since search is now just another version of the algo LAME!) But it feels like all YouTube content about Supabase is extremely outdated. All 2-3 years old. Which in the AI universe is ancient for a tool used by a lot of AI ppl.

English
25
1
30
12K
Sam
Sam@Guruu75·
@melvynx Most of people have no clue of rls and vibecode with it the same way as they would do on a usual Postgres, sometimes even without understanding anon key concept. That’s scary for data leakage.
English
0
0
1
31
Sam
Sam@Guruu75·
@MennelDev Tellement satisfaisant de faire ses propres solutions maison avec la vision exacte que tu en as
Français
0
0
1
137
Mennel 🏛️
Mennel 🏛️@MennelDev·
j'suis en train de remplacer toutes mes pages notion surchargées par des petits CRM super custom apres la PWA pour mon agence, je me fait mon app pour suivre mes app perso (benefices, calendrier paiement apple, dépenses marketing, influ, idées, tickets etc..) vive claude
Français
5
0
21
2.9K
Sam
Sam@Guruu75·
@confuse_geek @archiexzzz We learn everyday, that’s what matters. I’m new to mobile app on my end so that I’ll probably face similar questions. The more shiny solution is not always the best for our usecase or what we’re at ease with, so that I just stopped using supabase for this exact reason.
English
0
0
0
25
Khushal
Khushal@confuse_geek·
Web dev is new to me and I’m building a saas for a client. I used to build mobile apps and I’m good at that but web is new. What is did is all the important logic is at backend side fastapi. Only I need anon key in .env of frontend because of supabase auth. And obviously access token needed to be store in the frontend. Almost everything is new to me but supabse is littlebit fimilar so I went with this. Will try own db or proper managed postgres like neon, digital ocean managed postgres in future for sure.
English
1
0
1
94
Archie Sengupta
Archie Sengupta@archiexzzz·
Just hacked a VC-funded Voice AI company. I now have their prod data. I now have access to all: > medical information of customers > call recordings, phone numbers, contact names > email addresses > all SYSTEM_PROMPT for all agents they are running > API keys and Secrets > org data > OAuth Provider IDs > all webhook_events Mostly, I did IDOR and BAC attacks to get the data. I was able to retrieve all table columns and other access vulnerabilities. Once I had that, it was very easy to bypass and get all the data.
Archie Sengupta tweet media
English
135
84
2.3K
347.9K